From owner-svn-doc-all@FreeBSD.ORG Fri Jun 7 09:08:44 2013
Return-Path:
Table of Contents
Abstract
This document lists errata items for FreeBSD 8.4-RELEASE, + “®” symbol.
Table of Contents
Abstract
This document lists errata items for FreeBSD 8.4-RELEASE, containing significant information discovered after the release or too late in the release cycle to be otherwise included in the release documentation. @@ -37,7 +37,12 @@ contain up-to-date copies of this document (as of the time of the snapshot).
For a list of all FreeBSD CERT security advisories, see http://www.FreeBSD.org/security/ or ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/.
The following security advisories pertain to FreeBSD 8.4-RELEASE. For more information, consult the individual advisories available from - http://security.FreeBSD.org/.
Advisory | Date | Topic |
---|---|---|
SA-12:01.openssl | 03 May 2012 | OpenSSL multiple vulnerabilities |
SA-12:02.crypt | 30 May 2012 | Incorrect crypt() hashing |
SA-12:03.bind | 12 June 2012 | Incorrect handling of zero-length RDATA fields in named(8) |
SA-12:04.sysret | 12 June 2012 | Privilege escalation when returning from kernel |
SA-12:05.bind | 06 August 2012 | named(8) DNSSEC validation Denial of Service |
SA-12:06.bind | 22 November 2012 | Multiple Denial of Service vulnerabilities with named(8) |
SA-12:07.hostapd | 22 November 2012 | Insufficient message length validation for EAP-TLS messages |
SA-12:08.li nux | 22 November 2012 | Linux compatibility layer input validation error |
SA-13:02.libc | 19 February 2013 | glob(3) related resource exhaustion |
SA-13:03.openssl | 02 April 2013 | OpenSSL multiple vulnerabilities |
SA-13:04.bind | 02 April 2013 | BIND remote denial of service |
SA-13:05.nfsserver | 29 April 2013 | Insufficient input validation in the NFS server |
[20130606] The fxp(4) network interface driver may not + http://security.FreeBSD.org/.
Advisory | Date | Topic |
---|---|---|
SA-12:01.openssl | 03 May 2012 | OpenSSL multiple vulnerabilities |
SA-12:02.crypt | 30 May 2012 | Incorrect crypt() hashing |
SA-12:03.bind | 12 June 2012 | Incorrect handling of zero-length RDATA fields in named(8) |
SA-12:04.sysret | 12 June 2012 | Privilege escalation when returning from kernel |
SA-12:05.bind | 06 August 2012 | named(8) DNSSEC validation Denial of Service |
SA-12:06.bind | 22 November 2012 | Multiple Denial of Service vulnerabilities with named(8) |
SA-12:07.hostapd | 22 November 2012 | Insufficient message length validation for EAP-TLS messages |
SA-12:08.li nux | 22 November 2012 | Linux compatibility layer input validation error |
SA-13:02.libc | 19 February 2013 | glob(3) related resource exhaustion |
SA-13:03.openssl | 02 April 2013 | OpenSSL multiple vulnerabilities |
SA-13:04.bind | 02 April 2013 | BIND remote denial of service |
SA-13:05.nfsserver | 29 April 2013 | Insufficient input validation in the NFS server |
[20130607] The bge(4) network interface driver has an + issue when TSO (TCP Segmentation Offload) is enabled. It causes + intermittent reset and re-initialization.
A workaround is disabling the TSO feature. One can disable + it by adding the following line into the rc.conf(5) + file:
ifconfig_bge0
="-tso"
or by using the ifconfig(8) utility manually:
#
ifconfig
bge0
-tso
A patch to fix this issue will be released as an Errata + Notice.
[20130606] The fxp(4) network interface driver may not
work well with the dhclient(8) utility. More specifically,
if the /etc/rc.conf
has the following
line:
ifconfig_fxp0="DHCP"
to activate a DHCP client to configure the network