From owner-freebsd-security@freebsd.org Wed Nov 29 18:36:39 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 6197AE653FE for ; Wed, 29 Nov 2017 18:36:39 +0000 (UTC) (envelope-from delphij@gmail.com) Received: from mail-io0-x22c.google.com (mail-io0-x22c.google.com [IPv6:2607:f8b0:4001:c06::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 24C7B7FE52 for ; Wed, 29 Nov 2017 18:36:39 +0000 (UTC) (envelope-from delphij@gmail.com) Received: by mail-io0-x22c.google.com with SMTP id w127so4703525iow.11 for ; Wed, 29 Nov 2017 10:36:39 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=7t+bGkGZ/InlgWcQ5JmPXO6+SJ1Wps1leOaFFm4uRhA=; b=Ycnf8GRh3rMTQHUDgTXZFvSuO183Cf/sCU9hvkRrm9F9DXEYsu78U1gCE3iVZE5RDe ZmjXlkY4A/y9nmUTd0W1YvMor5GqnIml+Q/NWoeDKP+kt+MNFZHjBc+zNnS/vRE0vdsQ w8c7m1D5b8C7Mmw04tIwe+TrtbNUhS4UtBMagO4A/JyAHMSJGemT9bJYhUGMZC/qzvSx BOeV8m9dRpvz9A6uOXaYRrIcyNHGtJY2o2zmdXFp+lbWJZGvEHvetLCAh0jF0U1fs0tQ e3ux7XjxeSZ/UCgAXwz5EBDqTs1kfewsv39lxdI6qH+KVEHRtSulZ2QyUTW4dLnd9VOu yKeA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=7t+bGkGZ/InlgWcQ5JmPXO6+SJ1Wps1leOaFFm4uRhA=; b=RuIKsNgL7FH9jQNC69nSJq5KdgsfhnXQ5a/EP9ctyE+870LfB59OOIGkT4m+/cMPy1 KwCEwEB4GutF+gOMZifz/FmEDWeg12ASJE6me8ZzjXgAndReZVOOyG9ToOMIuOxLOltS f2Y96G8Yj6D+HhIVO29IGEK59z1l2o9SG5Hm4xQGTQpaLkH3eB76Qi86D7kW4IiEpExA D+TJqO01CjihzQtZF7/fy7h+LS+4Shv6EMqG3kmBX+uZ+C4EjnEL3I3v+DPWsJtYdKio BbZaa0jD5AlSZhUaC41I5TuhktPAHHMOuhKB3Bat8Yewlbzo9iV/Bh4jZAp8LBv+1s+f SnTA== X-Gm-Message-State: AJaThX6b+ZTMqydqENgGt68xD9jZ4zjA3k80L+v9B7PERDdZPMDNeHy6 HY7FM0w0uhsYnVJ647dx3RwUbaIrHWE+FuPsSmiqlw== X-Google-Smtp-Source: AGs4zMblfrlCFcLbYaPhifOhTnuveQEzQU8Xw/lVGA1oUUC9WGNjZ1JVaU2V5r+E2HaAtQUsc2SeB/JnqvOwvS/yetI= X-Received: by 10.107.137.82 with SMTP id l79mr4402357iod.271.1511980598198; Wed, 29 Nov 2017 10:36:38 -0800 (PST) MIME-Version: 1.0 Received: by 10.79.36.10 with HTTP; Wed, 29 Nov 2017 10:36:37 -0800 (PST) In-Reply-To: <20171129175111.GE9006@yz.kiev.ua> References: <20171129061559.3E4FCC99B@freefall.freebsd.org> <20171129175111.GE9006@yz.kiev.ua> From: Xin LI Date: Wed, 29 Nov 2017 10:36:37 -0800 Message-ID: Subject: Re: FreeBSD Security Advisory FreeBSD-SA-17:11.openssl To: "George L. Yermulnik" Cc: "freebsd-security@freebsd.org" Content-Type: text/plain; charset="UTF-8" X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Nov 2017 18:36:39 -0000 On Wed, Nov 29, 2017 at 9:51 AM, George L. Yermulnik wrote: > Hello! > > On Wed, 29 Nov 2017 at 06:15:59 (+0000), FreeBSD Security Advisories wrote: > > [...] >> 3) To update your vulnerable system via a source code patch: > >> The following patches have been verified to apply to the applicable >> FreeBSD release branches. > >> a) Download the relevant patch from the location below, and verify the >> detached PGP signature using your PGP utility. > >> [FreeBSD 10.3] >> # fetch https://security.FreeBSD.org/patches/SA-17:11/openssl-10.patch >> # fetch https://security.FreeBSD.org/patches/SA-17:11/openssl-10.patch.asc >> # gpg --verify openssl-10.patch.asc > [...] > > Is the patch above is indeed FreeBSD_10.3_specific as it might be > considered according to the block name ("[FreeBSD 10.3]")? > Would it apply cleanly on 10.4? Yes it would apply cleanly on 10.4.