.:[ packet storm ]:.
                             
the one stop shop
the one stop shop

 Section:  .. / advisories / freebsd  /

Page 1 of 11
<< 1 2 3 4 5 6 7 8 9 10 11 >> Files 1 - 25 of 257
Currently sorted by: Last ModifiedSort By: File Name, File Size

 ///  File Name: FreeBSD-SA-06:23.openssl-2.txt
Description:
FreeBSD Security Advisory: Multiple problems in crypto(3) [revised]
Homepage:http://security.FreeBSD.org/
File Size:15322
Last Modified:Oct 4 22:10:12 2006
MD5 Checksum:60c7185cf42783788adfe98d69d8c473

 ///  File Name: FreeBSD-SA-06-23.openssl.txt
Description:
FreeBSD Security Advisory: Multiple problems in crypto(3)
Homepage:http://www.freebsd.org/security/
File Size:14777
Last Modified:Oct 4 21:09:18 2006
MD5 Checksum:d6e58d7e1bd57fb91fc562d092c9cb67

 ///  File Name: FreeBSD-SA-06-20.bind.txt
Description:
FreeBSD Security Advisory - BIND 9 suffers from multiple denial of service vulnerabilities.
Homepage:http://www.freebsd.org/security/
File Size:6384
Related CVE(s):CVE-2006-4095, CVE-2006-4096
Last Modified:Sep 8 07:28:51 2006
MD5 Checksum:8417e3c29fcdaa164cdf36aa7fc72fa1

 ///  File Name: FreeBSD-SA-06-19.openssl.txt
Description:
FreeBSD Security Advisory - When verifying a PKCS#1 version 1.5 signature, OpenSSL ignores any bytes which follow the cryptographic hash being signed. In a valid signature there will be no such bytes.
Homepage:http://www.freebsd.org/security/
File Size:6222
Related CVE(s):CVE-2006-4339
Last Modified:Sep 8 07:27:29 2006
MD5 Checksum:566eca5458df286607558cd7ea7fe723

 ///  File Name: FreeBSD-SA-06-08.ppp.txt
Description:
FreeBSD Security Advisory - While processing Link Control Protocol (LCP) configuration options received from the remote host, ppp fails to correctly validate option lengths. This may result in data being read or written beyond the allocated kernel memory buffer.
Homepage:http://www.freebsd.org/security/
File Size:5596
Related CVE(s):CVE-2006-4304
Last Modified:Aug 28 02:01:06 2006
MD5 Checksum:e2f563d2dd4b544cc0d5325972985e5e

 ///  File Name: FreeBSD-SA-06-16.smbfs.txt
Description:
FreeBSD Security Advisory FreeBSD-SA-06:16.smbfs: smbfs does not properly sanitize paths containing a backslash character; in particular the directory name '..\' is interpreted as the parent directory by the SMB/CIFS server, but smbfs handles it in the same manner as any other directory.
Homepage:http://www.freebsd.org/security/
File Size:6001
Last Modified:Jun 2 00:49:20 2006
MD5 Checksum:6b5fe29e9c5f65d1e385ac5d1c9cce4b

 ///  File Name: FreeBSD-SA-06-15.ypserv.txt
Description:
FreeBSD Security Advisory FreeBSD-SA-06:15.ypserv: There are two documented methods of restricting access to NIS maps through ypserv(8): through the use of the /var/yp/securenets file, and through the /etc/hosts.allow file. While both mechanisms are implemented in the server, a change in the build process caused the "securenets" access restrictions to be inadvertently disabled.
Homepage:http://www.freebsd.org/security/
File Size:5136
Last Modified:Jun 2 00:48:47 2006
MD5 Checksum:29a262f243bd13cb49baa342002bac1c

 ///  File Name: FreeBSD-SA-06-14.fpu.txt
Description:
FreeBSD Security Advisory FreeBSD-SA-06:14.fpu - FPU information disclosure: On affected processors, a local attacker can monitor the execution path of a process which uses floating-point operations. This may allow an attacker to steal cryptographic keys or other sensitive information.
Homepage:http://www.freebsd.org/security/
File Size:7267
Last Modified:Apr 26 09:04:19 2006
MD5 Checksum:d416397c0cde6ec1455f60ec239ed5c6

 ///  File Name: FreeBSD-SA-06-13.sendmail.txt
Description:
FreeBSD-SA-06:13.sendmail - A remote attacker may be able to execute arbitrary code with the privileges of the user running sendmail, typically root.
Homepage:http://www.freebsd.org/security/
File Size:14505
Last Modified:Mar 23 21:52:47 2006
MD5 Checksum:6c86c0c2dcd02084ebd0b9cb562865c3

 ///  File Name: FreeBSD-SA-06-12.opie.txt
Description:
FreeBSD-SA-06:12.opie - The opiepasswd(1) program uses getlogin(2) to identify the user calling opiepasswd(1). In some circumstances getlogin(2) will return "root" even when running as an unprivileged user. This causes opiepasswd(1) to allow an unpriviled user to configure OPIE authentication for the root user.
Homepage:http://www.freebsd.org/security/
File Size:5587
Last Modified:Mar 23 21:52:17 2006
MD5 Checksum:a879cb7f04f38109a9c6770703b3deab

 ///  File Name: FreeBSD-SA-06-11.ipsec.txt
Description:
FreeBSD-SA-06:11.ipsec - An attacker able to to intercept IPSec packets can replay them. If higher level protocols which do not provide any protection against packet replays (e.g., UDP) are used, this may have a variety of effects.
Homepage:http://www.freebsd.org/security/
File Size:5448
Last Modified:Mar 23 21:49:33 2006
MD5 Checksum:00eb28e85d0a0489882135b4ee99b007

 ///  File Name: FreeBSD-SA-06-07.pf.txt
Description:
FreeBSD-SA-06:07.pf - IP fragment handling panic in pf(4)
Homepage:http://www.freebsd.org/security/
File Size:4374
Last Modified:Jan 26 06:15:52 2006
MD5 Checksum:f2ff92106829bc72041425d6489cb82d

 ///  File Name: FreeBSD-SA-06-06.kmem.txt
Description:
FreeBSD-SA-06:06.kmem - Local kernel memory disclosure.
Homepage:http://www.freebsd.org/security/
File Size:4039
Last Modified:Jan 26 06:15:18 2006
MD5 Checksum:c0be0dc046041baf3b8db0b2bb86d1ba

 ///  File Name: FreeBSD-SA-06-05.txt
Description:
FreeBSD-SA-06:05.80211 - An integer overflow in the handling of corrupt IEEE 802.11 beacon or probe response frames when scanning for existing wireless networks can result in the frame overflowing a buffer.
Homepage:http://www.freebsd.org/security/
File Size:3350
Last Modified:Jan 25 08:26:16 2006
MD5 Checksum:4d1a3110984d5ddd807e56852b3fd6ba

 ///  File Name: FreeBSD-SA-05-20.cvsbug.txt
Description:
FreeBSD Security Advisory FreeBSD-SA-05-20.cvsbug - A temporary file is created, used, deleted, and then re-created with the same name. This creates a window during which an attacker could replace the file with a link to another file.
Homepage:http://www.freebsd.org/security/
File Size:4753
Related CVE(s):CAN-2005-2693
Last Modified:Sep 8 03:02:42 2005
MD5 Checksum:144795693624779ec7d30b825746ea02

 ///  File Name: FreeBSD-SA-05-04.iconf.txt
Description:
The SIOCGIFCONF ioctl, used to request the kernel to produce a list of interfaces, can be exploited to reveal 12 bytes of memory. It is not at all guaranteed that this memory will contain anything interesting.
Homepage:http://www.freebsd.org/security/
File Size:4669
Last Modified:Apr 24 23:12:00 2005
MD5 Checksum:66eb4676bc3cd1b2175f219366017011

 ///  File Name: FreeBSD-SA-03:18.openssl
Description:
OpenSSL below v0.9.7c contain remotely exploitable vulnerabilities. More information available here.
Homepage:http://www.freebsd.org
File Size:7971
Related CVE(s):CAN-2003-0543, CAN-2003-0544
Last Modified:Oct 21 05:02:14 2003
MD5 Checksum:ed545da67a8f598d19279038ec39de28

 ///  File Name: FreeBSD-SA-03:07.sendmail
Description:
FreeBSD Security Advisory FreeBSD-SA-03:07 - A second remotely exploitable overflow was found in Sendmail header parsing. Upgrade to 8.12.9 to fix the vulnerability. Patch available here.
Homepage:http://www.freebsd.org/security
File Size:13358
Last Modified:Apr 1 10:01:15 2003
MD5 Checksum:454fb0ba212f0f2c02a50a53699667f4

 ///  File Name: FreeBSD-SA-03:04.sendmail
Description:
FreeBSD Security Advisory FreeBSD-SA-03:04.sendmail - ISS has identified a buffer overflow that may occur during header parsing in all versions of sendmail after version 5.79 through v8.12.7. Patch available here.
Homepage:http://www.freebsd.org/security
File Size:5645
Last Modified:Mar 3 19:14:45 2003
MD5 Checksum:282a5839a77da73bf290adf649ac1a1c

 ///  File Name: FreeBSD-SA-03:02.openssl
Description:
FreeBSD Security Advisory FreeBSD-SA-03:02 Version 1.1 - OpenSSL v0.9.6h and below contains a timing-based vulnerability in CBC ciphersuites in SSL and TLS which can recover fixed plaintext blocks, like a password.
Homepage:http://www.freebsd.org/security
Changes:Updated patches; corrected URLs.
File Size:113472
Last Modified:Feb 26 14:52:23 2003
MD5 Checksum:8c581cda70ad432693cef8f9ee3def2e

 ///  File Name: FreeBSD-SA-03:03.syncookies
Description:
FreeBSD Security Advisory FreeBSD-SA-03:03 - The FreeBSD syncookie implementation uses keys that are only 32 bits in length, allowing remote attackers to recover the ISN, which can be valid for up to four seconds, allowing ACL's to be bypassed and TCP connections forged. syncookies may be disabled using the `net.inet.tcp.syncookies' sysctl(8) by running the following command as root: "sysctl net.inet.tcp.syncookies=0".
Homepage:http://www.freebsd.org/security
File Size:4702
Last Modified:Feb 25 10:33:06 2003
MD5 Checksum:c63d88b8c3ba56ae9ba89de75ec0918e

 ///  File Name: FreeBSD-SA-03:01.cvs.txt
Description:
FreeBSD Security Advisory FreeBSD-SA-03:01 - It has been found that the CVS server can be tricked to free memory more then once, which can be used for remote code execution. Additionally, the CVS server allowed clients with write access to specify arbitrary commands to execute as part of an update (update-prog) or commit (checkin-prog). This behavior has been restricted. This affects all FreeBSD versions prior to 4.6-RELEASE-p7, 4.7-RELEASE-p4 and 5.0-RELEASE-p1.
Homepage:http://www.freebsd.org
File Size:7074
Last Modified:Feb 5 11:55:37 2003
MD5 Checksum:ccd2161dff5274f9b0a3ec177c73b23e

 ///  File Name: FreeBSD-SA-02:44.filedesc
Description:
FreeBSD Security Advisory FreeBSD-SA-02:44 - FreeBSD 4.3 and later is vulnerable to a local denial service attack due to a bug in the fpathconf system call which crashes the system by repeatedly calling fpathconf on a file descriptor until the reference count wraps to a negative value, then closing the file descriptor. See Pine-cert-20030101.txt for more information.
Homepage:http://www.freebsd.org/security
File Size:4035
Last Modified:Jan 9 09:57:48 2003
MD5 Checksum:afc45e10c1049f4c6192cae828f02f2d

 ///  File Name: FreeBSD-SA-02:43.bind
Description:
FreeBSD Security Advisory FreeBSD-SA-02:43.bind - BIND 8 has two vulnerabilities. The BIND SIG Cached RR overflow allows a remote attacker to force a server with recursion enabled to execute arbitrary code with the privileges of the name server process. The BIND OPT DoS and BIND SIG Expiry Time DoS may cause a remote name server to crash.
Homepage:http://www.freebsd.org/security/
File Size:10101
Last Modified:Nov 19 16:52:17 2002
MD5 Checksum:692cf77764884df59e8d5338ab9fa59f

 ///  File Name: FreeBSD-SA-02:41.smrsh
Description:
The sendmail restricted shell command, smrsh, has handling errors that will allow for command arguments with || or spaces to execute commands outside of its target directory. This shell was originally intended to replace /bin/sh to limit built-in shell commands being used via sendmail.
Homepage:http://www.freebsd.org
File Size:4704
Last Modified:Nov 17 06:10:53 2002
MD5 Checksum:56bc24cb1514d9e5c1f70e9ad3458284