From owner-svn-doc-projects@FreeBSD.ORG Tue Apr 2 22:58:01 2013 Return-Path: Delivered-To: svn-doc-projects@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id C55FA187; Tue, 2 Apr 2013 22:58:01 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) by mx1.freebsd.org (Postfix) with ESMTP id B61631E2; Tue, 2 Apr 2013 22:58:01 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.6/8.14.6) with ESMTP id r32Mw1IV083133; Tue, 2 Apr 2013 22:58:01 GMT (envelope-from gjb@svn.freebsd.org) Received: (from gjb@localhost) by svn.freebsd.org (8.14.6/8.14.5/Submit) id r32Mw06Q083112; Tue, 2 Apr 2013 22:58:00 GMT (envelope-from gjb@svn.freebsd.org) Message-Id: <201304022258.r32Mw06Q083112@svn.freebsd.org> From: Glen Barber Date: Tue, 2 Apr 2013 22:57:59 +0000 (UTC) To: doc-committers@freebsd.org, svn-doc-projects@freebsd.org Subject: svn commit: r41352 - in projects/ISBN_1-57176-407-0/share: pgpkeys security/advisories security/patches/SA-13:01 security/patches/SA-13:02 security/patches/SA-13:03 security/patches/SA-13:04 xml X-SVN-Group: doc-projects MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-doc-projects@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: SVN commit messages for doc projects trees List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Apr 2013 22:58:01 -0000 Author: gjb Date: Tue Apr 2 22:57:59 2013 New Revision: 41352 URL: http://svnweb.freebsd.org/changeset/doc/41352 Log: MFH: - Merged /head/share:r40977-41351 Approved by: doceng (implicit) Added: projects/ISBN_1-57176-407-0/share/pgpkeys/girgen.key - copied unchanged from r41351, head/share/pgpkeys/girgen.key projects/ISBN_1-57176-407-0/share/pgpkeys/tmseck.key - copied unchanged from r41351, head/share/pgpkeys/tmseck.key projects/ISBN_1-57176-407-0/share/security/advisories/FreeBSD-SA-13:01.bind.asc - copied unchanged from r41351, head/share/security/advisories/FreeBSD-SA-13:01.bind.asc projects/ISBN_1-57176-407-0/share/security/advisories/FreeBSD-SA-13:02.libc.asc - copied unchanged from r41351, head/share/security/advisories/FreeBSD-SA-13:02.libc.asc projects/ISBN_1-57176-407-0/share/security/advisories/FreeBSD-SA-13:03.openssl.asc - copied unchanged from r41351, head/share/security/advisories/FreeBSD-SA-13:03.openssl.asc projects/ISBN_1-57176-407-0/share/security/advisories/FreeBSD-SA-13:04.bind.asc - copied unchanged from r41351, head/share/security/advisories/FreeBSD-SA-13:04.bind.asc projects/ISBN_1-57176-407-0/share/security/patches/SA-13:01/ - copied from r41351, head/share/security/patches/SA-13:01/ projects/ISBN_1-57176-407-0/share/security/patches/SA-13:02/ - copied from r41351, head/share/security/patches/SA-13:02/ projects/ISBN_1-57176-407-0/share/security/patches/SA-13:03/ - copied from r41351, head/share/security/patches/SA-13:03/ projects/ISBN_1-57176-407-0/share/security/patches/SA-13:04/ - copied from r41351, head/share/security/patches/SA-13:04/ Modified: projects/ISBN_1-57176-407-0/share/pgpkeys/beech.key (contents, props changed) projects/ISBN_1-57176-407-0/share/pgpkeys/des.key projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys-developers.xml projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys.ent projects/ISBN_1-57176-407-0/share/xml/advisories.xml projects/ISBN_1-57176-407-0/share/xml/authors.ent projects/ISBN_1-57176-407-0/share/xml/commercial.consult.xml projects/ISBN_1-57176-407-0/share/xml/developers.ent projects/ISBN_1-57176-407-0/share/xml/navibar.ent projects/ISBN_1-57176-407-0/share/xml/news.xml projects/ISBN_1-57176-407-0/share/xml/press.xml projects/ISBN_1-57176-407-0/share/xml/release.ent Directory Properties: projects/ISBN_1-57176-407-0/share/ (props changed) Modified: projects/ISBN_1-57176-407-0/share/pgpkeys/beech.key ============================================================================== --- projects/ISBN_1-57176-407-0/share/pgpkeys/beech.key Tue Apr 2 18:08:38 2013 (r41351) +++ projects/ISBN_1-57176-407-0/share/pgpkeys/beech.key Tue Apr 2 22:57:59 2013 (r41352) @@ -1,35 +1,50 @@ -sub 1024g/F1FD1C3D 2011-08-29 +sub 2048g/960F45D9 2013-02-26 ]]> Modified: projects/ISBN_1-57176-407-0/share/pgpkeys/des.key ============================================================================== --- projects/ISBN_1-57176-407-0/share/pgpkeys/des.key Tue Apr 2 18:08:38 2013 (r41351) +++ projects/ISBN_1-57176-407-0/share/pgpkeys/des.key Tue Apr 2 22:57:59 2013 (r41352) @@ -1,288 +1,232 @@ uid Dag-Erling Smørgrav uid Dag-Erling Smørgrav -uid Dag-Erling Smørgrav -uid [jpeg image of size 3315] -sub 2048g/920C3313 2006-11-11 [expires: 2012-12-31] +uid [jpeg image of size 4779] +sub 4096R/F4DE87F5 2013-02-15 [expires: 2015-01-01] ]]> Copied: projects/ISBN_1-57176-407-0/share/pgpkeys/girgen.key (from r41351, head/share/pgpkeys/girgen.key) ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ projects/ISBN_1-57176-407-0/share/pgpkeys/girgen.key Tue Apr 2 22:57:59 2013 (r41352, copy of r41351, head/share/pgpkeys/girgen.key) @@ -0,0 +1,237 @@ + + + +uid [jpeg image of size 8260] +uid Palle Girgensohn +sub 2048R/6BC41243 2012-02-23 [expires: 2016-02-23] +]]> + Modified: projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys-developers.xml ============================================================================== --- projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys-developers.xml Tue Apr 2 18:08:38 2013 (r41351) +++ projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys-developers.xml Tue Apr 2 22:57:59 2013 (r41352) @@ -551,6 +551,11 @@ &pgpkey.pfg; + + &a.girgen; + &pgpkey.girgen; + + &a.pgollucci; &pgpkey.pgollucci; @@ -1516,6 +1521,11 @@ &pgpkey.matthew; + + &a.tmseck; + &pgpkey.tmseck; + + &a.stas; &pgpkey.stas; Modified: projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys.ent ============================================================================== --- projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys.ent Tue Apr 2 18:08:38 2013 (r41351) +++ projects/ISBN_1-57176-407-0/share/pgpkeys/pgpkeys.ent Tue Apr 2 22:57:59 2013 (r41352) @@ -134,6 +134,7 @@ + @@ -375,6 +376,7 @@ + Copied: projects/ISBN_1-57176-407-0/share/pgpkeys/tmseck.key (from r41351, head/share/pgpkeys/tmseck.key) ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ projects/ISBN_1-57176-407-0/share/pgpkeys/tmseck.key Tue Apr 2 22:57:59 2013 (r41352, copy of r41351, head/share/pgpkeys/tmseck.key) @@ -0,0 +1,49 @@ + + + +uid Thomas-Martin Seck (Privat) +uid Thomas-Martin Seck (FreeBSD) +sub 2048g/3DC33B0F 2000-11-22 +]]> + Copied: projects/ISBN_1-57176-407-0/share/security/advisories/FreeBSD-SA-13:01.bind.asc (from r41351, head/share/security/advisories/FreeBSD-SA-13:01.bind.asc) ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ projects/ISBN_1-57176-407-0/share/security/advisories/FreeBSD-SA-13:01.bind.asc Tue Apr 2 22:57:59 2013 (r41352, copy of r41351, head/share/security/advisories/FreeBSD-SA-13:01.bind.asc) @@ -0,0 +1,122 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA1 + +============================================================================= +FreeBSD-SA-13:01.bind Security Advisory + The FreeBSD Project + +Topic: BIND remote DoS with deliberately crafted DNS64 query + +Category: contrib +Module: bind +Announced: 2013-02-19 +Affects: FreeBSD 9.x and later +Corrected: 2013-01-08 09:05:09 UTC (stable/9, 9.1-STABLE) + 2013-02-19 13:27:20 UTC (releng/9.0, 9.0-RELEASE-p6) + 2013-02-19 13:27:20 UTC (releng/9.1, 9.1-RELEASE-p1) +CVE Name: CVE-2012-5688 + +For general information regarding FreeBSD Security Advisories, +including descriptions of the fields above, security branches, and the +following sections, please visit . + +I. Background + +BIND 9 is an implementation of the Domain Name System (DNS) protocols. +The named(8) daemon is an Internet Domain Name Server. + +DNS64 is an IPv6 transition mechanism that will return a synthesized +AAAA response even if there is only an A record available. + +II. Problem Description + +Due to a software defect a crafted query can cause named(8) to crash +with an assertion failure. + +III. Impact + +If named(8) is configured to use DNS64, an attacker who can send it a +query can cause named(8) to crash, resulting in a denial of service. + +IV. Workaround + +No workaround is available, but systems not configured to use DNS64 +using the "dns64" configuration statement are not vulnerable. DNS64 +is not enabled in the default configuration on FreeBSD. + +V. Solution + +Perform one of the following: + +1) Upgrade your vulnerable system to a supported FreeBSD stable or +release / security branch (releng) dated after the correction date. + +Restart the named(8) daemon, or reboot your system. + +2) To update your vulnerable system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +# fetch http://security.FreeBSD.org/patches/SA-13:01/bind.patch +# fetch http://security.FreeBSD.org/patches/SA-13:01/bind.patch.asc +# gpg --verify bind.patch.asc + +b) Execute the following commands as root: + +# cd /usr/src +# patch < /path/to/patch + +Recompile the operating system using buildworld and installworld as *** DIFF OUTPUT TRUNCATED AT 1000 LINES ***