NetBSD Security Advisory 2024-001: Inadequate validation of user-supplied hostname in utmp_update(8)

2024-03-10 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2024-001 = Topic: Inadequate validation of user-supplied hostname in utmp_update(8) Version:NetBSD-current: affected prior to 2023-09-30

NetBSD Security Advisory 2024-002: OpenSSH CVE-2024-6387 `regreSSHion'

2024-07-02 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2024-002 = Topic: OpenSSH CVE-2024-6387 `regreSSHion' Version:NetBSD-current: affected prior to 2024-07-02 NetBSD

NetBSD Security Advisory 2013-005: bind Denial of Service (CVE-2013-4854)

2013-07-30 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2013-005 = Topic: bind Denial of Service (CVE-2013-4854) Version:NetBSD-current: source prior to July 28th, 2013 NetBSD

NetBSD Security Advisory 2013-006: Arbitrary Kernel Read with netstat -P

2013-07-30 Thread NetBSD Security Officer
r finding the problem, and informing the NetBSD Security Officer about it. Revision History 2013-07-30 Initial release More Information Advisories may be updated as new information becomes available. The most recent version of this advisory (PGP s

NetBSD Security Advisory 2013-007: Protocol handling issues in X Window System client libraries

2013-07-30 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2013-007 = Topic: Protocol handling issues in X Window System client libraries Version:NetBSD-current: source prior to Jun 6th, 2013

NetBSD Security Advisory 2013-008: Error in authorization check re tcpdrop sysctl

2013-08-02 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2013-008 = Topic: Error in authorization check re tcpdrop sysctl Version:NetBSD-current: affected prior to Aug 2nd, 2013

NetBSD Security Advisory 2013-009: user settable small BPF buffer can cause a panic

2013-09-11 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2013-009 = Topic: user settable small BPF buffer can cause a panic Version:NetBSD-current: source prior to Sept 10th, 2013

NetBSD Security Advisory 2013-010: Use after free in Xserver handling of ImageText requests

2013-11-12 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2013-010 = Topic: Use after free in Xserver handling of ImageText requests Version:NetBSD-current: source prior to Oct 8th, 2013

NetBSD Security Advisory 2013-011: embryonic TCP sockets local DoS

2013-11-26 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2013-011 = Topic: embryonic TCP sockets local DoS Version:NetBSD-current: source prior to Nov 2nd, 2013 NetBSD 6.1 - 6.

NetBSD Security Advisory 2014-001: Stack buffer overflow in libXfont

2014-01-07 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-001 = Topic: Stack buffer overflow in libXfont Version:NetBSD-current: source prior to Tue 7th, 2014 NetBSD 6.1:

NetBSD Security Advisory 2014-002: ntpd used as DDoS amplifier

2014-01-07 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-002 = Topic: ntpd used as DDoS amplifier Version:NetBSD-current: source prior to Dec 27th, 2013 NetBSD 6.1:

NetBSD Security Advisory 2015-008: OpenSSL and TLS protocol vulnerabilities

2015-08-20 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2015-008 = Topic: OpenSSL and TLS protocol vulnerabilities Version:NetBSD-current: source prior to July 7th NetBSD 6.

NetBSD Security Advisory 2015-007: OpenSSL and SSLv3 vulnerabilities

2015-08-20 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2015-007 = Topic: OpenSSL and SSLv3 vulnerabilities Version:NetBSD-current: source prior to Mar 19th NetBSD 6.1 - 6.1

NetBSD Security Advisory 2015-009: TCP LAST_ACK state memory exhaustion

2015-10-21 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2015-009 = Topic: TCP LAST_ACK state memory exhaustion Version:NetBSD-current: source prior to Mon, Jul 24th 2015

NetBSD Security Advisory 2016-001: Multiple vulnerabilities in ntp daemon

2016-04-16 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2016-001 = Topic: Multiple vulnerabilities in ntp daemon Version:NetBSD-current: source prior to Fri, Oct 23 2015 NetB

NetBSD Security Advisory 2016-002: BDF file parsing issues in libXfont

2016-04-16 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2016-002 = Topic: BDF file parsing issues in libXfont Version:NetBSD-current: affected prior to 20150319 NetBSD 6.1 -

NetBSD Security Advisory 2016-003: Privilege escalation in calendar(1)

2016-04-16 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2016-003 = Topic: Privilege escalation in calendar(1) Version:NetBSD-current: source prior to Wed, Jul 1st 2015 NetBS

NetBSD Security Advisory 2016-004: Multiple vulnerabilities in the compatibility layers

2016-04-21 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2016-004 = Topic: Multiple vulnerabilities in the compatibility layers Version:NetBSD current: source prior to Sat, Aug 8th 2015

NetBSD Security Advisory 2016-005: bozohttpd CGI handlers potential remote code execution

2016-04-21 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2016-005 = Topic: bozohttpd CGI handlers potential remote code execution Version:NetBSD-current: 20160415 NetBSD 7.0:

NetBSD Security Advisory 2017-001: Memory leak in the connect system call

2017-01-21 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2017-001 = Topic: Memory leak in the connect system call Version:NetBSD-current: source prior to Sun, Oct 31st 2016 Ne

NetBSD Security Advisory 2020-001: Missing permissions checks for network ioctls

2020-01-21 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2020-001 = Topic: Missing permissions checks for network ioctls Version:NetBSD-current: affected NetBSD 9.0_RC1:

NetBSD Security Advisory 2020-002: Specific ICMPv6 error message packet can crash the system

2020-03-10 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2020-002 = Topic: Specific ICMPv6 error message packet can crash the system Version:NetBSD-current: affected untill January 23, 2020

NetBSD Security Advisory 2020-003: USB network interface jumbo packets

2020-10-13 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2020-003 = Topic: USB network interface jumbo packets Version:NetBSD-current: affected prior to 2020-08-28 NetBSD 9*

NetBSD Security Advisory 2021-001: Predictable ID disclosures in IPv4 and IPv6

2021-03-11 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2021-001 = Topic: Predictable ID disclosures in IPv4 and IPv6 Version:NetBSD-current: affected NetBSD 9.1:

NetBSD Security Advisory 2014-003: posix_spawn unbounded kernel memory allocation

2014-03-05 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-003 = Topic: posix_spawn unbounded kernel memory allocation Version:NetBSD-current: affected prior to 2014-02-02

NetBSD Security Advisory 2014-004: OpenSSL information disclosure ("heartbleed")

2014-04-09 Thread NetBSD Security Officer
`uname -m`-heartbleedfix.tgz ftp http://ftp.netbsd.org/pub/NetBSD/misc/heartbleed/SHA512 ftp http://ftp.netbsd.org/pub/NetBSD/misc/heartbleed/SHA512.asc gpg --verify SHA512.asc # check for: Good signature from "NetBSD Security Officer " cksum -a sha512 netbsd6-`uname -m`-heartbleedfix.tgz &

NetBSD Security Advisory 2014-005: libXfont multiple vulnerabilities

2014-05-28 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-005 = Topic: libXfont multiple vulnerabilities Version:NetBSD-current: source prior to May 13th, 2014 NetBSD 6.1 -

NetBSD Security Advisory 2014-006: Multiple OpenSSL vulnerabilities

2014-06-09 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-006 = Topic: Multiple OpenSSL vulnerabilities Version:NetBSD-current: June 5th, 2014 NetBSD 6.1 - 6.1.4: affec

NetBSD Security Advisory 2014-007: bozohttpd basic http authentication bypass

2014-07-17 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-007 = Topic: bozohttpd basic http authentication bypass Version:NetBSD-current: 20140708 NetBSD 6.1*:

NetBSD Security Advisory 2014-008: Multiple OpenSSL vulnerabilities

2014-08-27 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-008 = Topic: Multiple OpenSSL vulnerabilities Version:NetBSD-current: prior to Aug 10th, 2014 NetBSD 6.1 - 6.1.4:

NetBSD Security Advisory 2014-009: Multiple vulnerabilities in the execve system call

2014-08-27 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-009 = Topic: Multiple vulnerabilities in the execve system call Version:NetBSD-current: source prior to Fri, Feb 14th 2014

NetBSD Security Advisory 2014-010: Multiple vulnerabilities in the compatibility layers

2014-08-27 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-010 = Topic: Multiple vulnerabilities in the compatibility layers Version:NetBSD-current: source prior to Tue, Apr 15th 2014

NetBSD Security Advisory 2014-011: User-controlled memory allocation in the modctl system call

2014-08-27 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-011 = Topic: User-controlled memory allocation in the modctl system call Version:NetBSD-current: source prior to Thu, Jul 10th 201

NetBSD Security Advisory 2014-008: Multiple OpenSSL vulnerabilities (updated)

2014-09-03 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-008 = Topic: Multiple OpenSSL vulnerabilities Version:NetBSD-current: prior to Aug 10th, 2014 NetBSD 6.1 - 6.1.4:

NetBSD Security Advisory 2014-009: Multiple vulnerabilities in the execve system call

2014-09-08 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-009 = Topic: Multiple vulnerabilities in the execve system call Version:NetBSD-current: source prior to Fri, Feb 14th 2014

NetBSD Security Advisory 2014-010: Multiple vulnerabilities in the compatibility layers

2014-09-08 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-010 = Topic: Multiple vulnerabilities in the compatibility layers Version:NetBSD-current: source prior to Tue, Apr 15th 2014

NetBSD Security Advisory 2014-011: User-controlled memory allocation in the modctl system call

2014-09-08 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-011 = Topic: User-controlled memory allocation in the modctl system call Version:NetBSD-current: source prior to Thu, Jul 10th 201

NetBSD Security Advisory 2014-012: Memory leak in the setsockopt system call

2014-09-08 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-012 = Topic: Memory leak in the setsockopt system call Version:NetBSD-current: source prior to Sat, Aug 16th 2014

NetBSD Security Advisory 2014-013: ftp(1) can be made to execute arbitrary commands by a malicious webserver

2014-11-03 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-013 = Topic: ftp(1) can be made to execute arbitrary commands by a malicious webserver Version:NetBSD-current: sou

NetBSD Security Advisory 2014-014: Multiple vulnerabilities in the mount system call

2014-11-03 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-014 = Topic: Multiple vulnerabilities in the mount system call Version:NetBSD-current: source prior to Sun, Apr 20th 2014

NetBSD Security Advisory 2014-015: OpenSSL and SSLv3 vulnerabilities

2014-11-03 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2014-015 = Topic: OpenSSL and SSLv3 vulnerabilities Version:NetBSD-current: source prior to Oct 18th, 2014 NetBSD 6.1 -

NetBSD Security Advisory 2015-001: Protocol handling issues in X Window System servers

2015-01-08 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2015-001 = Topic: Protocol handling issues in X Window System servers Version:NetBSD-current: affected prior to 2014-12-22

NetBSD Security Advisory 2015-002: bind Denial of Service (CVE-2014-8500)

2015-01-08 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2015-002 = Topic: bind Denial of Service (CVE-2014-8500) Version:NetBSD-current: source prior to Dec 10, 2014 NetBSD 7

NetBSD Security Advisory 2015-003: NTPd multiple vulnerabilities (CVE-2014-929[3-6])

2015-03-23 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2015-003 = Topic: NTPd multiple vulnerabilities (CVE-2014-929[3-6]) Version:NetBSD-current: source prior to Dec 19, 2014

NetBSD Security Advisory 2015-004: Two vulnerabilities in the compatibility layers

2015-03-23 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2015-004 = Topic: Two vulnerabilities in the compatibility layers Version:NetBSD-current: source prior to Fri, Oct 10th 2014

NetBSD Security Advisory 2015-005: buffer overflow in libevent (CVE-2014-6272)

2015-03-23 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2015-005 = Topic: buffer overflow in libevent (CVE-2014-6272) Version:NetBSD-current: source prior to Jan 29th NetBSD 6

NetBSD Security Advisory 2015-006: OpenSSL and SSLv3 vulnerabilities

2015-03-23 Thread NetBSD Security Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2015-006 = Topic: OpenSSL and SSLv3 vulnerabilities Version:NetBSD-current: source prior to Jan 14th NetBSD 6.1 - 6.1.5

NetBSD Security Advisory 2021-001: Predictable ID disclosures in IPv4 and IPv6

2021-07-14 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2021-001 = Topic: Predictable ID disclosures in IPv4 and IPv6 Version:NetBSD-current: affected NetBSD 9.1:

NetBSD Security Advisory 2021-002: Incorrect permissions in kernfs

2021-07-14 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2021-002 = Topic: Incorrect permissions in kernfs Version:NetBSD-current: affected between March 3, 2020 and July 6, 2021

NetBSD Security Advisory 2022-001:

2022-05-10 Thread NetBSD Security-Officer
-BEGIN PGP MESSAGE- owGFWH2MVNUVZ0EqO+2oGAUsoBe1uCsz82ZXFpZRhHVYYIXF6S6ujWL1fdyZee57 7z7uvW+HwRaVaq2KFoFAY7RGU1ttajRpJZRqakljrcaP+ofEGmqwtmnV+oGipq3a c+59b3Z2We1CwrDv3vPxO7/zO+fN9vSUlmktt8w/febRd/s+b3n2bXnqOiovGlyR HezpzHd2ZvP5jpzcJK3N1y1rbSX6GRmkdsRdWSc9zogrGK+T5Gw6BaeW/r+fdCqd Ws9C1y60

NetBSD Security Advisory 2022-002: Coredump credential reference count leak

2022-10-02 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2022-002 = Topic: Coredump credential reference count leak Version:NetBSD-current: affected prior to 2022-09-10 Ne

NetBSD Security Advisory 2022-002: Coredump credential reference count leak

2022-10-04 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2022-002 = Topic: Coredump credential reference count leak Version:NetBSD-current: affected prior to 2022-09-10 Ne

NetBSD Security Advisory 2022-003: Race condition in mail.local(8)

2022-10-04 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2022-003 = Topic: Race condition in mail.local(8) Version:NetBSD-current: affected prior to 2022-05-17 NetBSD 10:

NetBSD Security Advisory 2022-004: procfs(5) missing permission checks

2022-10-04 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2022-004 = Topic: procfs(5) missing permission checks Version:NetBSD-current: affected prior to 2022-06-18 NetBSD

NetBSD Security Advisory 2023-001: Multiple buffer overflows in USB drivers

2023-06-28 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-001 = Topic: Multiple buffer overflows in USB drivers Version:NetBSD-current: affected up to 9.99.32 NetBSD 1

NetBSD Security Advisory 2023-002: Various compatibility syscall memory access issues

2023-06-28 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-002 = Topic: Various compatibility syscall memory access issues Version:NetBSD-current: affected before 2020-05-15

NetBSD Security Advisory 2023-003: Structure padding memory disclosures

2023-06-28 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-003 = Topic: Structure padding memory disclosures Version:NetBSD-current: affected prior to 2021-09-09 NetBSD

NetBSD Security Advisory 2023-004: procfs environ exposure

2023-06-28 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-004 = Topic: procfs environ exposure Version:NetBSD-current: affected prior to 9.99.78 NetBSD 10.0_BETA:

NetBSD Security Advisory 2023-005: su(1) bypass via pam_ksu(8)

2023-06-28 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-005 = Topic: su(1) bypass via pam_ksu(8) Version:NetBSD-current: affected prior to 2023-06-20 NetBSD 10.0_BET

NetBSD Security Advisory 2023-006: KDC-spoofing in pam_krb5

2023-06-28 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-006 = Topic: KDC-spoofing in pam_krb5 Version:NetBSD-current: affected prior to 2023-06-20 NetBSD 10.0_BETA:

NetBSD Security Advisory 2023-007: multiple vulnerabilities in ftpd(8)

2023-11-16 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NetBSD Security Advisory 2023-007 = Topic: multiple vulnerabilities in ftpd(8) Version:NetBSD-current: affected prior to 2023-10-01 NetBSD 10.0_BET

NetBSD Security Advisory 2018-009: bozohttpd can allow access to .htpasswd

2018-12-11 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-009 = Topic: bozohttpd can allow access to .htpasswd Version:NetBSD-current: prior to 2018-11-22 NetBSD 8*:

NetBSD Security Advisory 2019-001: Several kernel memory disclosure bugs

2019-02-06 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2019-001 = Topic: Several kernel memory disclosure bugs Version:NetBSD-current: source prior to Thu, Jan 31st 2019 Ne

NetBSD Security Advisory 2019-002: Unprivileged kernel memory overwrite in mq_send(3)

2019-05-02 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2019-002 = Topic: Unprivileged kernel memory overwrite in mq_send(3) Version:NetBSD-current: affected prior to April 16, 2019

NetBSD Security Advisory 2019-003: Unprivileged user kernel stack disclosure in SIOCGIFCONF

2019-05-02 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2019-003 = Topic: Unprivileged user kernel stack disclosure in SIOCGIFCONF Version:NetBSD-current: affected prior to April 15, 2019

NetBSD Security Advisory 2019-004: IPv6 neighbor cache leak on expiration

2019-08-08 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2019-004 = Topic: IPv6 neighbor cache leak on expiration Version:NetBSD-current: affected up to 8.99.51 NetBSD 8.1:

NetBSD Security Advisory 2019-005: Sysctl RNG Key Erasure

2019-11-26 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2019-005 = Topic: Sysctl RNG Key Erasure Version:NetBSD-current: affected prior to 2019-11-25 NetBSD 8*:

NetBSD Security Advisory 2019-006: Denial of service and possible privilege escallation in filemon

2019-12-16 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2019-006 = Topic: Denial of service and possible privilege escallation in filemon Version:NetBSD-current: affected up to 9.99.17

NetBSD Security Advisory 2017-002: Several vulnerabilities in ARP

2017-02-17 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2017-002 = Topic: Several vulnerabilities in ARP Version:NetBSD-current: source prior to Tue, Jan 24th 2017 NetBSD 7.0

NetBSD Security Advisory 2017-003: Xen-amd64: weak privilege separation

2017-03-24 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2017-00X = Topic: Xen-amd64: weak privilege separation Version:NetBSD-current: source prior to Sun, Mar 5th 2017 NetB

NetBSD Security Advisory 2017-004: buffer overflow via cmap for 4 graphics drivers

2017-09-08 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2017-004 = Topic: buffer overflow via cmap for 4 graphics drivers Version:NetBSD-current: source prior to June 13th Ne

NetBSD Security Advisory 2017-005: x86: vulnerabilities in context handling

2017-09-08 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2017-005 = Topic: x86: vulnerabilities in context handling Version:NetBSD-current: source prior to Sun, Jul 1st 2017 N

NetBSD Security Advisory 2017-006: Vnode reference leak in the openat system call

2017-09-08 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2017-006 = Topic: Vnode reference leak in the openat system call Version:NetBSD-current: source prior to Sun, July 9th 2017

NetBSD Security Advisory 2018-001: Several vulnerabilities in context handling

2018-01-02 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-001 = Topic: Several vulnerabilities in context handling Version:NetBSD-current: source prior to Sat, Sep 2nd 2017

NetBSD Security Advisory 2018-002: Local DoS in virecover

2018-01-02 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-002 = Topic: Local DoS in virecover Version:NetBSD-current: source prior to Sat, November 4th 2017 NetBSD 7.0 -

NetBSD Security Advisory 2018-003: Remote DoS in IPsec (IPv6)

2018-02-12 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-003 = Topic: Remote DoS in IPsec (IPv6) Version:NetBSD-current: source prior to Wed, Jan 24th 2018 NetBSD 7.1:

NetBSD Security Advisory 2018-004: Remote Memory Corruption in IPv6

2018-02-12 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-004 = Topic: Remote Memory Corruption in IPv6 Version:NetBSD-current: source prior to Tue, Jan 30th 2018 NetBSD 7

NetBSD Security Advisory 2018-003: Remote DoS in IPsec (IPv6)

2018-04-09 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-003 = Topic: Remote DoS in IPsec (IPv6) Version:NetBSD-current: source prior to Wed, Jan 24th 2018 NetBSD 7.1:

NetBSD Security Advisory 2018-004: Remote Memory Corruption in IPv6

2018-04-09 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-004 = Topic: Remote Memory Corruption in IPv6 Version:NetBSD-current: source prior to Tue, Jan 30th 2018 NetBSD 7

NetBSD Security Advisory 2018-005: Privilege separation bug in Xen-amd64

2018-04-09 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-005 = Topic: Privilege separation bug in Xen-amd64 Version:NetBSD-current: source prior to Sun, Dec 31st 2017 Net

NetBSD Security Advisory 2018-006: Several vulnerabilities in the network stack

2018-04-09 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-006 = Topic: Several vulnerabilities in the network stack Version:NetBSD-current: source prior to Fri, Feb 9th 2018

NetBSD Security Advisory 2018-007: Several vulnerabilities in IPsec

2018-05-07 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-007 = Topic: Several vulnerabilities in IPsec Version:NetBSD-current: source prior to Tue, May 1st 2018 NetBSD 7.

NetBSD Security Advisory 2018-008: Several vulnerabilities in NPF

2018-05-24 Thread NetBSD Security-Officer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 NetBSD Security Advisory 2018-008 = Topic: Several vulnerabilities in NPF Version:NetBSD-current: source prior to Thu, Mar 22nd 2018 NetBSD 7.1