From owner-svn-doc-all@FreeBSD.ORG Thu Jun 13 05:53:08 2013
Return-Path:
Table of Contents
Abstract
This document lists errata items for FreeBSD 8.4-RELEASE, + “®” symbol.
Table of Contents
Abstract
This document lists errata items for FreeBSD 8.4-RELEASE, containing significant information discovered after the release or too late in the release cycle to be otherwise included in the release documentation. @@ -37,7 +37,10 @@ contain up-to-date copies of this document (as of the time of the snapshot).
For a list of all FreeBSD CERT security advisories, see http://www.FreeBSD.org/security/ or ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/.
The following security advisories pertain to FreeBSD 8.4-RELEASE. For more information, consult the individual advisories available from - http://security.FreeBSD.org/.
| Advisory | Date | Topic |
|---|---|---|
| SA-12:01.openssl | 03 May 2012 | OpenSSL multiple vulnerabilities |
| SA-12:02.crypt | 30 May 2012 | Incorrect crypt() hashing |
| SA-12:03.bind | 12 June 2012 | Incorrect handling of zero-length RDATA fields in named(8) |
| SA-12:04.sysret | 12 June 2012 | Privilege escalation when returning from kernel |
| SA-12:05.bind | 06 August 2012 | named(8) DNSSEC validation Denial of Service |
| SA-12:06.bind | 22 November 2012 | Multiple Denial of Service vulnerabilities with named(8) |
| SA-12:07.hostapd | 22 November 2012 | Insufficient message length validation for EAP-TLS messages |
| SA-12:08.li nux | 22 November 2012 | Linux compatibility layer input validation error |
| SA-13:02.libc | 19 February 2013 | glob(3) related resource exhaustion |
| SA-13:03.openssl | 02 April 2013 | OpenSSL multiple vulnerabilities |
| SA-13:04.bind | 02 April 2013 | BIND remote denial of service |
| SA-13:05.nfsserver | 29 April 2013 | Insufficient input validation in the NFS server |
[20130609] There is incompatibility in jail(8) + http://security.FreeBSD.org/.
| Advisory | Date | Topic |
|---|---|---|
| SA-12:01.openssl | 03 May 2012 | OpenSSL multiple vulnerabilities |
| SA-12:02.crypt | 30 May 2012 | Incorrect crypt() hashing |
| SA-12:03.bind | 12 June 2012 | Incorrect handling of zero-length RDATA fields in named(8) |
| SA-12:04.sysret | 12 June 2012 | Privilege escalation when returning from kernel |
| SA-12:05.bind | 06 August 2012 | named(8) DNSSEC validation Denial of Service |
| SA-12:06.bind | 22 November 2012 | Multiple Denial of Service vulnerabilities with named(8) |
| SA-12:07.hostapd | 22 November 2012 | Insufficient message length validation for EAP-TLS messages |
| SA-12:08.li nux | 22 November 2012 | Linux compatibility layer input validation error |
| SA-13:02.libc | 19 February 2013 | glob(3) related resource exhaustion |
| SA-13:03.openssl | 02 April 2013 | OpenSSL multiple vulnerabilities |
| SA-13:04.bind | 02 April 2013 | BIND remote denial of service |
| SA-13:05.nfsserver | 29 April 2013 | Insufficient input validation in the NFS server |
[20130613] The vtnet(4) network interface driver + displays the following message upon configuration when using + QEMU 1.4.1 and later:
vtnet0: error setting host MAC filter table
This message is harmless when the interface has only one MAC + address. The patch for this issue is filed to a PR kern/178955.
[20130609] There is incompatibility in jail(8)
configuration because the jail(8) utility and
rc.d/jail script has been changed. More
specifically, the following sysctl(8) variables cannot be