From owner-freebsd-security@FreeBSD.ORG Fri May 20 15:41:24 2005 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4723E16A4CE for ; Fri, 20 May 2005 15:41:24 +0000 (GMT) Received: from web32712.mail.mud.yahoo.com (web32712.mail.mud.yahoo.com [68.142.206.25]) by mx1.FreeBSD.org (Postfix) with SMTP id C7A6243D7C for ; Fri, 20 May 2005 15:41:23 +0000 (GMT) (envelope-from stheg_olloydson@yahoo.com) Received: (qmail 15173 invoked by uid 60001); 20 May 2005 15:41:20 -0000 Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; b=lK0Atk1RlSM4LthSbfc9z85BStKZC/Uoa+oPlEiFqpe8CbOGjs5LJGT8ZydHf6J3CoH3TTni3uYdZVkeP3CFcFZef8lsJ/yUZpqI9YD9wtzcZwjrA6rhRqIM2dARsMlqXOGC/RdH4u5QZEh3MQKiZtpBi2+JR5VbDy8JbU5jwOo= ; Message-ID: <20050520154120.15171.qmail@web32712.mail.mud.yahoo.com> Received: from [68.157.29.120] by web32712.mail.mud.yahoo.com via HTTP; Fri, 20 May 2005 08:41:19 PDT Date: Fri, 20 May 2005 08:41:19 -0700 (PDT) From: stheg olloydson To: freebsd-security@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Subject: patch schedule for TCP timestamp issue X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 May 2005 15:41:24 -0000 Hello, I see by the commit logs that the so-called PAWS vulnerability was fixed in -current on April 10. Could you, please, say when a patch will be released? Given the hole's low threat-level, this is not a pressing matter; so if the plan is to wait until the possible tcpdump and gzip issues are investigated and fixed (if necessary) so that a "3 for the price of 1" patch-set is released, that would be reasonable. Thanks, stheg Discover Yahoo! Stay in touch with email, IM, photo sharing and more. Check it out! http://discover.yahoo.com/stayintouch.html