Commit graph

25 commits

Author SHA1 Message Date
Xin LI
62d937ff2f Remove a line that is not supposed to be in the advisory.
Noticed by:	pluknet
2014-01-14 22:21:52 +00:00
Xin LI
dcb9c59cc2 Add 4 latest advisories and 2 latest errata notices:
Fix bsnmpd remote denial of service vulnerability. [SA-14:01]

Fix ntpd distributed reflection Denial of Service vulnerability.
[SA-14:02]

Fix OpenSSL multiple vulnerabilities. [SA-14:03]

Fix BIND remote denial of service vulnerability. [SA-14:04]

Disable hardware RNGs by default. [EN-14:01]

Fix incorrect coalescing of stack entry with mmap. [EN-14:02]
2014-01-14 19:57:49 +00:00
Xin LI
494b6033e6 Correct sshd_config path.
Noticed by:	cstdenis at ctgameinfo.com
2013-11-29 01:08:37 +00:00
Xin LI
a5b8f65bdb Add latest errata notice:
Fix error in patch for FreeBSD-EN-13:04.freebsd-update [EN-13:05].
2013-11-29 01:02:00 +00:00
Dag-Erling Smørgrav
f57acf6c24 Pre-zero the MAC context.
Security:	CVE-2013-4548
Security:	FreeBSD-SA-13:14.openssh
Approved by:	so
2013-11-19 10:20:35 +00:00
Xin LI
20f8872397 Correct a typo.
Submitted by:	Kenta Suzumoto <kentas hush com>
2013-10-26 20:36:08 +00:00
Xin LI
5686fe11cf Add latest errata notice:
Fix multiple freebsd-update bugs that break upgrading to
FreeBSD 10.0. [EN-13:04]
2013-10-26 20:21:27 +00:00
Dag-Erling Smørgrav
18d8e0c127 mjg@ has asked not to be credited.
Approved by:	so
2013-09-10 11:01:30 +00:00
Dag-Erling Smørgrav
1febdc15b9 Missed some Xs.
Approved by:	so
2013-09-10 10:55:15 +00:00
Dag-Erling Smørgrav
c4d9a19be3 Fix the length calculation for the final block of a sendfile(2)
transmission which could be tricked into rounding up to the nearest
page size, leaking up to a page of kernel memory.  [13:11]

In IPv6 and NetATM, stop SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFDSTADDR
and SIOCSIFNETMASK at the socket layer rather than pass them on to the
link layer without validation or credential checks.  [SA-13:12]

Prevent cross-mount hardlinks between different nullfs mounts of the
same underlying filesystem.  [SA-13:13]

Security:	CVE-2013-5666
Security:	FreeBSD-SA-13:11.sendfile
Security:	CVE-2013-5691
Security:	FreeBSD-SA-13:12.ifioctl
Security:	CVE-2013-5710
Security:	FreeBSD-SA-13:13.nullfs
Approved by:	so
2013-09-10 10:31:23 +00:00
Dag-Erling Smørgrav
e8346ce7d0 Patches for SA-13:09 and SA-13:10 were retroactively released for 9.2-RC1.
Approved by:	so
2013-09-10 10:25:27 +00:00
Xin LI
b735a9d213 Add two latest advisories:
Fix an integer overflow in computing the size of a temporary buffer
can result in a buffer which is too small for the requested
operation. [13:09]

Fix a bug that could lead to kernel memory disclosure with
SCTP state cookie. [13:10]

Add latest errata notices:

Fix a data corruption problem with mfi(4) operating on > 2TB
disks in a JBOD. [EN-13:03]
2013-08-22 01:12:09 +00:00
Xin LI
223eda903e Add two latest advisories:
Fix Denial of Service vulnerability in named(8). [13:07]

  Fix a bug that allows remote client bypass the normal
  access checks when when -network or -host restrictions are
  used at the same time with -mapall. [13:08]
2013-07-27 03:39:12 +00:00
Xin LI
bf74ae0e2e Add latest errata notices:
Fix a problem where dhclient(8) utility tries to initilaize an
  fxp(4) forever because the driver resets the controller chip
  twice upon initialization. [EN-13:01]

  Fix a problem where frames sent to additional MAC addresses are
  not forwarded to the vtnet(4) interface. [EN-13:02]
2013-06-28 05:58:41 +00:00
Xin LI
bf1c404ec6 Commit revised advisory for 13:06.mmap. 2013-06-21 21:41:48 +00:00
Dag-Erling Smørgrav
037314c9bc Fix a bug that allowed a tracing process (e.g. gdb) to write
to a memory-mapped file in the traced process's address space
even if neither the traced process nor the tracing process had
write access to that file.

Security:	CVE-2013-2171
Security:	FreeBSD-SA-13:06.mmap
Approved by:	so
2013-06-18 07:17:53 +00:00
Dag-Erling Smørgrav
4ebf8b68aa Revised advisory. 2013-04-29 21:56:02 +00:00
Dag-Erling Smørgrav
d1056d0259 Fix a bug that allows NFS clients to issue READDIR on files.
PR:		kern/178016
Security:	CVE-2013-3266
Security:	FreeBSD-SA-13:05.nfsserver
Approved by:	so
2013-04-29 20:53:58 +00:00
Xin LI
04b880b25a Add latest security advisories:
Fix OpenSSL multiple vulnerabilities. [13:03]

  Fix BIND remote denial of service. [13:04]

Security:	CVE-2013-0166, CVE-2013-0169
Security:	FreeBSD-SA-13:03.openssl
Security:	CVE-2013-2266
Security:	FreeBSD-SA-13:04.bind
2013-04-02 18:01:39 +00:00
Bjoern A. Zeeb
fef748c3be Add latest security advisories:
Fix Denial of Service vulnerability in named(8) with DNS64. [13:01]

  Fix Denial of Service vulnerability in libc's glob(3) functionality.
  [13:02]

Security:	CVE-2012-5688
Security:	FreeBSD-SA-13:01.bind
Security:	CVE-2010-2632
Security:	FreeBSD-SA-13:02.libc
2013-02-19 13:56:49 +00:00
Simon L. B. Nielsen
2974adeecf Fix Subversion revision ID's in SA-12:07.hostapd.
Reported by:	pluknet
2012-11-23 00:34:39 +00:00
Simon L. B. Nielsen
79c48ea54e Add resigned SA-12:07.hostapd fix fixes a bad URL. 2012-11-22 23:57:58 +00:00
Simon L. B. Nielsen
26913edc9f Add latest advisories. 2012-11-22 23:46:26 +00:00
Gabor Kovesdan
2e51ec7022 - Strip unnecessary trailing spaces
Approved by:	doceng (implicit)
2012-08-21 19:16:02 +00:00
Bjoern A. Zeeb
3571e53040 Import FreeBSD Security Advisories and Errata Notices, as well as their
patches for easier mirroring, to eliminate a special copy, to make
www.freebsd.org/security a full copy of security.freebsd.org and be
eventually be the same.

For now files are just sitting there.   The symlinks are missing.

Discussed on:	www (repository location)
Discussed with:	simon (so)
2012-08-15 06:19:40 +00:00