2 Security Advisories

The following security advisories pertain to FreeBSD 5.5-RELEASE. For more information, consult the individual advisories available from http://security.FreeBSD.org/.

Advisory Date Topic
SA-06:15.ypserv 31 May 2006

Inoperative access controls in ypserv(8)

SA-06:16.smbfs 31 May 2006

smbfs chroot escape

SA-06:17.sendmail 14 June 2006

Incorrect multipart message handling in Sendmail

SA-06:18.ppp 23 August 2006

Buffer overflow in sppp(4)

SA-06:19.openssl 06 September 2006

Incorrect PKCS#1 v1.5 padding validation in crypto(3)

SA-06:20.bind 06 September 2006

Denial of Service in named(8)

SA-06:21.gzip 19 September 2006

Multiple vulnerabilities in gzip(1)

SA-06:22.openssh 30 September 2006

Multiple vulnerabilities in OpenSSH

SA-06:23.openssl 28 September 2006

Multiple problems in crypto(3)

SA-06:25.kmem 6 December 2006

Kernel memory disclosure in firewire(4)

SA-06:26.gtar 6 December 2006

gtar(1) name mangling symlink vulnerability

SA-07:01.jail 11 January 2007

Jail rc.d script privilege escalation

SA-07:02.bind 9 February 2007

Multiple Denial of Service vulnerabilities in named(8)

SA-07:03.ipv6 26 April 2007

IPv6 Routing Header 0 is dangerous

SA-07:05.libarchive 12 July 2007

Errors handling corrupt tar files in libarchive(3)

SA-07:09.random 29 November 2007

Random value disclosure

SA-07:10.gtar 29 November 2007

gtar(1) directory traversal vulnerability

SA-08:01.pty 14 January 2008

pty snooping

SA-08:03.sendfile 14 February 2008

sendfile(2) write-only file permission bypass

SA-08:04.ipsec 14 February 2008

IPsec null pointer dereference panic

SA-08:05.openssh 17 April 2008

OpenSSH X11-forwarding privilege escalation

This file, and other release-related documents, can be downloaded from http://www.FreeBSD.org/snapshots/.

For questions about FreeBSD, read the documentation before contacting <questions@FreeBSD.org>.

All users of FreeBSD 5-STABLE should subscribe to the <stable@FreeBSD.org> mailing list.

For questions about this documentation, e-mail <doc@FreeBSD.org>.