Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 03 Sep 1998 12:04:25 -0700
From:      Studded <Studded@dal.net>
To:        freebsd-hackers@FreeBSD.ORG
Subject:   Response to RST validation problem?
Message-ID:  <35EEE839.D3169E59@dal.net>

next in thread | raw e-mail | index | archive | help
As I'm sure everyone is aware, there was a post on bugtraq Sunday
regarding a vulnerability in our TCP code which leaves the system open
to attack via RST packets. In the past the project has always responded
within a few days to such problems, either with a fix or a progress
report on a fix. I have not seen such a response, therefore I'm asking
what progress is being made on this problem.

	This bug is being used against some of our servers, although it's far
from our biggest problem. Basically I'd like to be able to tell the 20
or so sysadmins on our network that use FreeBSD, "Please plan to upgrade
your kernel sometime in the next N days," where N is a reasonable
approximation of when a patch will be ready. 

	According to Darren Reed the appropriate fix is already available in
NetBSD's code, so that might be a good place to start looking. :)

Thanks in advance,

Doug
-- 
***           Chief Operations Officer, DALnet IRC network          ***

At Barry (a small town in south Wales) hidden cameras have had to be
installed to keep watch on the town's CCTV [Closed Circuit Television]
to record acts of vandalism against the CCTV. - Privacy Forum

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?35EEE839.D3169E59>