From owner-svn-src-stable-9@FreeBSD.ORG Fri Jan 6 05:03:23 2012 Return-Path: Delivered-To: svn-src-stable-9@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 443C8106564A; Fri, 6 Jan 2012 05:03:23 +0000 (UTC) (envelope-from hrs@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:4f8:fff6::2c]) by mx1.freebsd.org (Postfix) with ESMTP id 314828FC0C; Fri, 6 Jan 2012 05:03:23 +0000 (UTC) Received: from svn.freebsd.org (localhost [127.0.0.1]) by svn.freebsd.org (8.14.4/8.14.4) with ESMTP id q0653NLE072628; Fri, 6 Jan 2012 05:03:23 GMT (envelope-from hrs@svn.freebsd.org) Received: (from hrs@localhost) by svn.freebsd.org (8.14.4/8.14.4/Submit) id q0653NYm072626; Fri, 6 Jan 2012 05:03:23 GMT (envelope-from hrs@svn.freebsd.org) Message-Id: <201201060503.q0653NYm072626@svn.freebsd.org> From: Hiroki Sato Date: Fri, 6 Jan 2012 05:03:23 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-9@freebsd.org X-SVN-Group: stable-9 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Cc: Subject: svn commit: r229683 - stable/9/release/doc/en_US.ISO8859-1/relnotes X-BeenThere: svn-src-stable-9@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: SVN commit messages for only the 9-stable src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 06 Jan 2012 05:03:23 -0000 Author: hrs Date: Fri Jan 6 05:03:22 2012 New Revision: 229683 URL: http://svn.freebsd.org/changeset/base/229683 Log: - Update copyright year. - Add SA-11:0[12456789] and -11:10. - Update the upgrade section. Modified: stable/9/release/doc/en_US.ISO8859-1/relnotes/article.sgml Modified: stable/9/release/doc/en_US.ISO8859-1/relnotes/article.sgml ============================================================================== --- stable/9/release/doc/en_US.ISO8859-1/relnotes/article.sgml Fri Jan 6 02:28:21 2012 (r229682) +++ stable/9/release/doc/en_US.ISO8859-1/relnotes/article.sgml Fri Jan 6 05:03:22 2012 (r229683) @@ -20,17 +20,7 @@ $FreeBSD$ - 2000 - 2001 - 2002 - 2003 - 2004 - 2005 - 2006 - 2007 - 2008 - 2009 - 2010 + 2012 The &os; Documentation Project @@ -132,9 +122,97 @@ Security Advisories - - - + Problems described in the following security advisories have + been fixed. For more information, consult the individual + advisories available from + . + + + + + + + + + Advisory + Date + Topic + + + + + + SA-11:01.mountd + 20 April 2011 + Network ACL mishandling in &man.mountd.8; + + + + SA-11:02.bind + 28 May 2011 + BIND remote DoS with large RRSIG RRsets and negative + caching + + + + SA-11:04.compress + 28 September 2011 + Errors handling corrupt compress file in + &man.compress.1; and &man.gzip.1; + + + + SA-11:05.unix + 28 September 2011 + Buffer overflow in handling of UNIX socket + addresses + + + + SA-11:06.bind + 23 December 2011 + Remote packet Denial of Service against &man.named.8; + servers + + + + SA-11:07.chroot + 23 December 2011 + Code execution via chrooted ftpd + + + + SA-11:08.telnetd + 23 December 2011 + telnetd code execution vulnerability + + + + SA-11:09.pam_ssh + 23 December 2011 + pam_ssh improperly grants access when user account has + unencrypted SSH private keys + + + + SA-11:10.pam + 23 December 2011 + pam_start() does not validate + service names + + + + + Kernel Changes @@ -544,17 +622,11 @@ binary upgrades between RELEASE versions (and snapshots of the various security branches) are supported using the &man.freebsd-update.8; utility. The binary upgrade procedure will - update unmodified userland utilities, as well as unmodified GENERIC or - SMP kernels distributed as a part of an official &os; release. + update unmodified userland utilities, as well as a unmodified GENERIC kernel + distributed as a part of an official &os; release. The &man.freebsd-update.8; utility requires that the host being upgraded have Internet connectivity. - An older form of binary upgrade is supported through the - Upgrade option from the main &man.sysinstall.8; - menu on CDROM distribution media. This type of binary upgrade - may be useful on non-&arch.i386;, non-&arch.amd64; machines - or on systems with no Internet connectivity. - Source-based upgrades (those based on recompiling the &os; base system from source code) from previous versions are supported, according to the instructions in