From owner-freebsd-security@freebsd.org Sun May 19 12:32:44 2019 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 1053415ACF2D for ; Sun, 19 May 2019 12:32:44 +0000 (UTC) (envelope-from doctor@doctor.nl2k.ab.ca) Received: from doctor.nl2k.ab.ca (doctor.nl2k.ab.ca [204.209.81.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) server-signature RSA-PSS (4096 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 79A418AF8A for ; Sun, 19 May 2019 12:32:43 +0000 (UTC) (envelope-from doctor@doctor.nl2k.ab.ca) Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.92 (FreeBSD)) (envelope-from ) id 1hSKzQ-0004KM-AH for freebsd-security@freebsd.org; Sun, 19 May 2019 06:32:32 -0600 Date: Sun, 19 May 2019 06:32:32 -0600 From: The Doctor To: freebsd-security@freebsd.org Subject: RDS Flaw in Linsuck Message-ID: <20190519123232.GA13039@doctor.nl2k.ab.ca> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.11.4 (2019-03-13) X-Rspamd-Queue-Id: 79A418AF8A X-Spamd-Bar: + X-Spamd-Result: default: False [1.38 / 15.00]; ARC_NA(0.00)[]; FROM_HAS_DN(0.00)[]; R_SPF_ALLOW(-0.20)[+a]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; NEURAL_HAM_LONG(-0.69)[-0.693,0]; NEURAL_SPAM_MEDIUM(0.01)[0.014,0]; RCPT_COUNT_ONE(0.00)[1]; RCVD_TLS_LAST(0.00)[]; NEURAL_SPAM_SHORT(0.88)[0.883,0]; MX_GOOD(-0.01)[cached: doctor.nl2k.ab.ca]; DMARC_POLICY_ALLOW(-0.50)[nl2k.ab.ca,quarantine]; INTRODUCTION(2.00)[]; FROM_EQ_ENVFROM(0.00)[]; R_DKIM_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:6171, ipnet:204.209.81.0/24, country:CA]; MID_RHS_MATCH_FROM(0.00)[]; IP_SCORE(-0.02)[country: CA(-0.09)]; RCVD_COUNT_TWO(0.00)[2] X-Mailman-Approved-At: Sun, 19 May 2019 12:57:07 +0000 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 19 May 2019 12:32:44 -0000 Does the RDS flaw CVE-2019-1181 affect BSD? -- Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising! https://www.empire.kred/ROOTNK?t=94a1f39b Look at Psalms 14 and 53 on Atheism Australia avoiding voting for any Republican Candidates on 19 May 2019 From owner-freebsd-security@freebsd.org Sun May 19 14:00:55 2019 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id CDD4E15AEC3A for ; Sun, 19 May 2019 14:00:54 +0000 (UTC) (envelope-from frenezahomo@gmail.com) Received: from mail-ed1-x52b.google.com (mail-ed1-x52b.google.com [IPv6:2a00:1450:4864:20::52b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 7CD528D660 for ; Sun, 19 May 2019 14:00:53 +0000 (UTC) (envelope-from frenezahomo@gmail.com) Received: by mail-ed1-x52b.google.com with SMTP id e24so19270408edq.6 for ; Sun, 19 May 2019 07:00:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to; bh=AbArlXDUXgyBYQQpfubchFRVQSQgZtt3ReDQoHR+dmg=; b=rLabkxSnn8wymdKDS7VgBlSz7peGYv/SF935ZlP54/Mxn6BFkh6dZ5zNzRhZHguKq8 wDxqQh6jUq8oVyZ40XG7/4W3iclKrVvrylxWoaWKIsFBgfjzuNmesT0aB5h/ClMNRAuC GDX+IzwwxMuhN44QIaFSiWBS4W2JiYUXWWpyc+CjOD+dVSYAZFc8woLOce6M3JS5rUHS gtkug0K1xS5lrDyOwVJqUDwQR1MP1vQxmu5wJdlwzS/K/75jOepWclHDutDb2KKZVqYS hLRHMS+n1Tw1quqUjT+6mx3u3xjiYNSNP1SBAzGQhi+p9U7tCaeRusVKQvv6EvmhuNam j+BA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to; bh=AbArlXDUXgyBYQQpfubchFRVQSQgZtt3ReDQoHR+dmg=; b=G7158JyAHQXX5mctTPila9+dcIj8UFXufBLWDSgfDQrOJ+Mqq+xd0V2npbstysPdcN N5rlKyCTk6IiGQf9p6NvaXKLPAkeyQyGWl/Ee9MbFc+0IaEuaLZOeWaqpoVd/8XjNqPh YKBt01C/fpiapCogyu03zxhU9OcC+i0maqDUZfFXMnOh1h1Uk5Oyyoia1wgy3XaN8OCd upueWIVdKg0jaZnLKlKfS5o/HDzL3sCt4BbTSBfTMBsQAOM08oSHpZ6MxOzVfvDOr/Iz RI0Kch2Z3TteC2qJIY/8HFTSxFG5e8bPnCuCKT/rBcXoSMop1PQbmY3BAOfL13SMqYHk IW9Q== X-Gm-Message-State: APjAAAWAY/xD6xszvfW1oWsyDpu/0NYXXtkGNIqRTVLL6yNGBn1eo7xE HvVv9kFcBLJggOD+U7xZ3YF02kQf X-Google-Smtp-Source: APXvYqz7K3vzthdUhE2zhgZq/QsVGpN37vkuxqvPU0AaWDEEJ/+ZAExlV5+fSYfJ2BhT6+/ogzaARQ== X-Received: by 2002:a50:b865:: with SMTP id k34mr70851853ede.16.1558274450730; Sun, 19 May 2019 07:00:50 -0700 (PDT) Received: from [0.0.0.0] (exit3.tor-network.net. [31.220.0.225]) by smtp.gmail.com with ESMTPSA id r2sm1184576ejz.80.2019.05.19.07.00.48 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 19 May 2019 07:00:49 -0700 (PDT) Subject: Re: RDS Flaw in Linsuck To: freebsd-security@freebsd.org References: <20190519123232.GA13039@doctor.nl2k.ab.ca> From: frenza Openpgp: preference=signencrypt Autocrypt: addr=frenezahomo@gmail.com; keydata= mQINBFwC2jYBEAC7XQ+Z6Nwl7xt307wjuwFZc32M11Inds2otl6RrNR4F7m7M32ApqnvJ6y6 BX1/RCZrIZyqFmLVQq6IP8UK69Aiqgj/dmjdENicIOATxIF3iT83DyYArQiZnEtSOXeXWpWP cL1VT9oO1kFY0jgaLozeT89hu7vTn6INHucRgSGIMTi33peGdWpRWeG7FD78dA196mAmGmrS QBHWLvzWGx2wc2xcQZoOfjXIew358PHLfA4UslIYLvfzf+zAwY7DQ6FDZX03+NV4efdjQnGX ukH2k5JYFwy1q9rcgLlUnkMUzr6xC2FXrut9l2uz0jHzPzA6s3qYWlwp22+W08ZUb/YPDYQJ iLqlIKXQZZfVarbbuphhqJv86k6vpg3XTRTgzeGvdBVB3eXP8csIj4i0IhHKjw2kd6kb9m6E D5JGmggSUu4y4ykxpcmfBBGLkRLBr5+9my7yxgr3xT3kpMmNRp4E/iLeeLquwwxfvHJaUo7c vbOLHL9IyFQnbMVxNKxTZyWl4ntqyA/89ZTfaczFh94hcBHoACQsHJCRzVOpk7FuOsZM6yCQ em+oieBOBQaBOfUrriA73h/2kmtrPeOzv5o2kgihMMILpaZ2v9wyAjiUTlog//v7SL6qZ5P/ AM7m8L9scBMLUeLboinUjN2kqTazqntcPQJsfUD7kPOXhNiF3QARAQABtCRGcmVuZXphIEhv bW8gPGZyZW5lemFob21vQGdtYWlsLmNvbT6JAk4EEwEIADgCGwMFCwkIBwIGFQoJCAsCBBYC AwECHgECF4AWIQSfz0lsy5QSubqUPgaL4w9A+whqFgUCXNwZ3AAKCRCL4w9A+whqFjGAEACT 77atJr0OjxFrd1utYaWP0vAbCymqbnRNqDEldqWFo0/0cha2Bjt/L8IhNWfCca83YJc4MBa3 4URsQpqANqgrgmp9Uojy6WRgt329dEX274ZPVRGt0MfTd+Vtngvu3JaFO0rR4qCSKHvhnRJO WsVIIw3HULmqfD+0UBRP1OSUeBAJ10NXRaHdoxnnGwsW57ceClje5cFT4XAnX86vxa/Ak2z/ ydKsGgVPfdum5dzgj6OqTlAemEgciLsbPgKIiaI5hX+tx3PcWz5VHZQnS85TMpiEao7rhYOi hrx59HMVrYJh1iv+//+hNnKUnSbuxGM8fOoU6qp/UrLeXYc1z0VPB38S1EZHwv1/wG7qGe02 6rPLmHvZZin6FzcmtOh07R/P5wz0eDs5KkS+aa5S3P6Usg3Xm2MzNQ3LBVCktF6/8k7egcMt myplXawjsmN6s6+O2MG9uh5CtcJTapTIC0e6MDPTfE99eHthnibrxu/OX6RDpHIvd3/+1hjn WOXtCw1/IMebdkCB2Kr7ficVr7tqrs+FL79shFQXDQb2qZPmZcJPWoIptQ/sY8n/+qiKZKoR 2Lrgs4C0LWvQueCWjnRqT/u2TDElsobL8cUi89ihrpwtGcjyZCH8yEAv67s9YfJ5j5WgYNUg E6VXPT8RGz/nNXU238ylmmM+lnTjkC6xnrkCDQRcAto2ARAAwjr3t28WObzSZPyTnwTMhN4X pPYObRyAB0ats8Z0+wa0e+xnJ0N6ohFjm9oGgE9JSZMba++eY5YOhtlamKIE2/maqAB9Sp98 XIrjmDCtzWcJv4l++aqR1MzPERPTH7fpVa572EcUTXhXwROZHwOtZtPqo5W8fyqcoA2z8vNH ma6OuojK6/qqOITUWs30cz8b8NCgzzhDq2Ys4XEjpCRWD0ypaFXV+ope+B28VL5jrH5GpRKn N1wm00jXjRuCdy95EeJf5n+VGhmwaS3AdCmDZzflo4j8GV31Zta6RHeEH1BoI+NXD6NDWj9g GG4V+S/f0niXDpd2Cw1pk59+1xP4lF6LhvI0I/buzIcBGz0aelrTCHtVditH3z8qf/o4YrL/ KxfySFTr+qqJ9e9onMbKFsaPgSbp/1gK+F9/CpMSs5R2wVDKi1z/Lg+wJbSf8IVZP0x5Msuu CFkp1jr3BQRLk8u7oYKJU3QOSXC9iZsU3P85yVdqx/dy3/6fgY32DZBhHsNjaGAf3GSkOJlr AhuORHYf/Jnc5CeeksEwqHXLktIpsQFZEOLmZCJ8zws1SfAPzsoCD6Mpb0f9ToGp4x+eRk2S NZ4TtZ8HahFC+pfOEzItq6XVNZTuvF9YmemVXvXcyO/7GU2fmUBxs9Tvt4a0+UfgI1bw9kgO 9HWPLp9ynq8AEQEAAYkCNgQYAQgAIAIbDBYhBJ/PSWzLlBK5upQ+BovjD0D7CGoWBQJc3Bny AAoJEIvjD0D7CGoWt8AP/0u+6iBAUD7AWjmy7wTYL+9o4eq6Dlv7oI1ec2fgIr0DqovzXE7/ /8wkgGq1xqGkjsoorxX+Bb2yXigJ5PnTrw/4GsYS7gJWEmeTFC4r3qN5IZpPb3rcZ/Zodz9o TrIjKJ9wlEM2NgTHcPIGQ9zUnpQa6QPtw44SosyOnh9yLJ8nPin5Q1PZDXazjNel8k2SUVKd Esteh9HUwJS9tkWv/03bvqMw9Q7RG/yg/IKU/VpsChRwZ+vwvP+k8n2o9ndK/XDJfpEfIzFe beKcrmm4QzPG9QXKd+JbkEadXWbANwnxK5/TpIwnqr1iZjw+dSXwrUizC5zPIXLzzUg1WsF4 x/th2nHalVxIQ6a8kWFtsVe5M1WQW0JNG+4f7uu8kr0BUtOMeKkUkh2Oa8pryp8yO9gOOTRH 1/4mNJwNhr0vnaDfAIVKAmCSMWwjb8KVfT2xjApcRIw/UKjN0BbvogVwCC+AC9k9LBgWLZ6N EUjong7SMt57/i76C43K5trk07PfsI6VtQAPe5GFlVQWS3DRJsm/vDMjHmtcUkZOSloiCyyW yqNjF6CZQzGjiJc9MfYQK7dRjn67Jf1x6ZWf6wWdId0xvK0AemomRxQCpIJM5w9bDwUyNmEU hdtIrNwrfUc3GqJYBZH5FCEhjKw0HzU0iRvw1sFTPtLa+SLV0CGT/MQx Message-ID: <370cfb93-0cc1-3410-0efa-b1102255eb47@gmail.com> Date: Sun, 19 May 2019 17:00:40 +0300 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 In-Reply-To: <20190519123232.GA13039@doctor.nl2k.ab.ca> Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="DUBzvfGQY2Q2YdGUFyDH28YBTiVg68TWO" X-Rspamd-Queue-Id: 7CD528D660 X-Spamd-Bar: -------- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20161025 header.b=rLabkxSn; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of frenezahomo@gmail.com designates 2a00:1450:4864:20::52b as permitted sender) smtp.mailfrom=frenezahomo@gmail.com X-Spamd-Result: default: False [-8.77 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; FREEMAIL_FROM(0.00)[gmail.com]; R_SPF_ALLOW(-0.20)[+ip6:2a00:1450:4000::/36]; HAS_ATTACHMENT(0.00)[]; TO_DN_NONE(0.00)[]; RCVD_COUNT_THREE(0.00)[3]; DKIM_TRACE(0.00)[gmail.com:+]; MX_GOOD(-0.01)[cached: alt3.gmail-smtp-in.l.google.com]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; NEURAL_HAM_SHORT(-0.96)[-0.960,0]; SIGNED_PGP(-2.00)[]; FROM_EQ_ENVFROM(0.00)[]; RCVD_TLS_LAST(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:+]; FREEMAIL_ENVFROM(0.00)[gmail.com]; ASN(0.00)[asn:15169, ipnet:2a00:1450::/32, country:US]; MID_RHS_MATCH_FROM(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com.dwl.dnswl.org : 127.0.5.0]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20161025]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; MIME_GOOD(-0.20)[multipart/signed,multipart/mixed,text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; RCPT_COUNT_ONE(0.00)[1]; IP_SCORE(-2.70)[ip: (-8.96), ipnet: 2a00:1450::/32(-2.20), asn: 15169(-2.27), country: US(-0.06)]; RCVD_IN_DNSWL_NONE(0.00)[b.2.5.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.4.6.8.4.0.5.4.1.0.0.a.2.list.dnswl.org : 127.0.5.0] X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 19 May 2019 14:00:55 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --DUBzvfGQY2Q2YdGUFyDH28YBTiVg68TWO Content-Type: multipart/mixed; boundary="nqJXLW7ZjQauvLHFhIf7r9q5bmjVc1tTu"; protected-headers="v1" From: frenza To: freebsd-security@freebsd.org Message-ID: <370cfb93-0cc1-3410-0efa-b1102255eb47@gmail.com> Subject: Re: RDS Flaw in Linsuck References: <20190519123232.GA13039@doctor.nl2k.ab.ca> In-Reply-To: <20190519123232.GA13039@doctor.nl2k.ab.ca> --nqJXLW7ZjQauvLHFhIf7r9q5bmjVc1tTu Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Content-Language: en-US Does FreeBSD support RDS in the first place? On 5/19/19 3:32 PM, The Doctor via freebsd-security wrote: > Does the RDS flaw CVE-2019-1181 affect BSD? > --nqJXLW7ZjQauvLHFhIf7r9q5bmjVc1tTu-- --DUBzvfGQY2Q2YdGUFyDH28YBTiVg68TWO Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEn89JbMuUErm6lD4Gi+MPQPsIahYFAlzhYY0ACgkQi+MPQPsI ahbBAw//cGAHGEIcuG5b68w8uD8aWlnkYfC4neFoIsGFsPkWsViKVseVyh7fqC9k n2tAbVhsguTWS8U93IIQvzSfyy7Aqu+J4DbqDnJsTg+ASIDDcRKN9HDLYpzCyjHD Xn3xRQVtbzQFbvDAJNowEW82b2tv5wjOdIMZ2mxoo23wEawL0CFpUVLA2nSfkXva NztLdjMObStCqBocmGZ6qxq8mKNu/O+5BK3XFr0TxyyE4I6aygQW0y3gAeLrPq/S o4OBA9mY4Pn2gvYXCl+qwrA4kEKxhemfnYgV9eKgiZoeb4/qB1WEyLQVUa6w6zxx D50LMnqDcAS4oDZ75KAAI/jftVttl5zHN4pIz1/Jj+aRehj6f8vyueaek+tyjTOa UmQlXIIzZ9Sp1wxEOZ9cAIljYasC93oOEwIJqgQ5Qg81b1t91IfM4soDEdzjRoRt eTpSavbesjKsl8oGoYkySyXbz02REBcA9sum8t2oxRabEJPEW1whXX1sgmiSxrXX 64ntnOkRog0g6/sNUaVQgL49er8SurD/AF2gbLUvOGaIVlDgmPa0qkJ4yUk50VvR 0LXjvKQ9IUn+UKH75LmfN/e9NPNd64RzySX2Z7Smh/bWnMAkgpDFTyvds7sFo+7+ dVfN20ctAtGMAzcDKHpMMZ4wQMoGWZTB4mu5RL2uWxFXKFKJ7QA= =pE5c -----END PGP SIGNATURE----- --DUBzvfGQY2Q2YdGUFyDH28YBTiVg68TWO--