From owner-freebsd-security@freebsd.org Fri Jan 12 02:20:51 2018 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E55B4E68A30 for ; Fri, 12 Jan 2018 02:20:51 +0000 (UTC) (envelope-from freebsd-security-local@be-well.ilk.org) Received: from be-well.ilk.org (be-well.ilk.org [23.30.133.173]) by mx1.freebsd.org (Postfix) with ESMTP id C1C8771261 for ; Fri, 12 Jan 2018 02:20:51 +0000 (UTC) (envelope-from freebsd-security-local@be-well.ilk.org) Received: by be-well.ilk.org (Postfix, from userid 1147) id 3069033C3E; Thu, 11 Jan 2018 21:20:43 -0500 (EST) From: Lowell Gilbert To: Brahmanand Reddy Cc: freebsd-security@freebsd.org Subject: Re: Need FreeBSD-SA-00:52(TCP uses weak initial sequence numbers) latest patch References: Reply-To: freebsd-security@freebsd.org Date: Thu, 11 Jan 2018 21:20:43 -0500 In-Reply-To: (Brahmanand Reddy's message of "Thu, 11 Jan 2018 22:13:48 +0530") Message-ID: <44k1wnes1w.fsf@be-well.ilk.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 12 Jan 2018 02:20:52 -0000 Brahmanand Reddy writes: >> >> Dear Team, >> >> Thanks for responding. >> >> Please share the corresponding FreeBSD-SA-00:52(*TCP uses weak initial >> sequence numbers*) latest patch. >> >> the original problem reported on : >> https://www.freebsd.org/security/advisories/FreeBSD-SA-00%3A52.tcp-iss.asc >> >> below list of similar CVEs >> >> CVE-2001-0328 >> CVE- 1999-0077 >> CVE-2000-0916 >> >> >> Thanks and regards, >> Brahma Those reports were fixed in FreeBSD almost 20 years ago, so you already have the fixes. Moreover, it seems silly to worry about minor security patches when you're running a FreeBSD release that has been out of support for over a year.