From owner-freebsd-security@freebsd.org Fri Apr 29 11:18:55 2016 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0FB48B20D0F for ; Fri, 29 Apr 2016 11:18:55 +0000 (UTC) (envelope-from gabor@zahemszky.hu) Received: from smtp-3-out.integrity.hu (smtp-3-out.integrity.hu [212.52.165.213]) by mx1.freebsd.org (Postfix) with ESMTP id B72041ADE for ; Fri, 29 Apr 2016 11:18:54 +0000 (UTC) (envelope-from gabor@zahemszky.hu) Received: from webmail.integrity.hu (mail-fe-1.integrity.hu [10.1.64.120]) by mail-smtp.integrity.hu (Postfix) with ESMTPA id 8211E40329 for ; Fri, 29 Apr 2016 13:13:21 +0200 (CEST) Received: from +Oqy66MTEcckkNdeGS/+JeMunA4hvTPA by webmail.integrity.hu with HTTP (HTTP/1.1 POST); Fri, 29 Apr 2016 13:13:21 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit Date: Fri, 29 Apr 2016 13:13:21 +0200 From: gabor@zahemszky.hu To: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-16:16.ntp In-Reply-To: <20160429082953.DB31D1769@freefall.freebsd.org> References: <20160429082953.DB31D1769@freefall.freebsd.org> Message-ID: <9e6342a420259fec7bd21d6222cc6e05@zahemszky.hu> X-Sender: gabor@zahemszky.hu User-Agent: Roundcube Webmail/1.1.4 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 29 Apr 2016 11:18:55 -0000 > 2) To update your vulnerable system via a binary patch: > > Systems running a RELEASE version of FreeBSD on the i386 or amd64 > platforms can be updated via the freebsd-update(8) utility: > > # freebsd-update fetch > # freebsd-update install Both on an i386 and on an amd64 machine, I got: ==== .... Fetching metadasa signature for 10.3-RELEASE from update5.freebsd.org... done Fetching metadata index.... done The update metadata is correctly signed, but failed an integrity check. Cowardly refusing to proceed any further. ==== Both machines are VM-s, upgraded from 10.2. (Got the same with -s update[23456].freebsd.org, and without -s option. Zahy < Gabor at Zahemszky dot HU >