[Midnightbsd-cvs] [MidnightBSD/src] 794f84: This commit was manufactured by cvs2svn to create ...

Lucas Holt noreply at github.com
Mon Mar 16 11:52:10 EDT 2020


  Branch: refs/heads/stable/0.4
  Home:   https://github.com/MidnightBSD/src
  Commit: 794f8404f9d2e98d29613e20260600eeeaece364
      https://github.com/MidnightBSD/src/commit/794f8404f9d2e98d29613e20260600eeeaece364
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-12 (Wed, 12 Jun 2013)

  Changed paths:
    A .gitignore
    M contrib/expat/lib/xmltok_impl.c
    M contrib/mDNSResponder/mDNSShared/dnssd_clientstub.c
    M contrib/one-true-awk/FIXES
    M contrib/one-true-awk/awkgram.y
    M contrib/one-true-awk/lex.c
    M contrib/one-true-awk/lib.c
    M contrib/one-true-awk/makefile
    M contrib/one-true-awk/maketab.c
    M contrib/one-true-awk/proctab.c
    M crypto/openssl/apps/openssl.cnf
    M crypto/openssl/apps/speed.c
    M crypto/openssl/apps/spkac.c
    M crypto/openssl/apps/x509.c
    M crypto/openssl/crypto/asn1/asn1.h
    M crypto/openssl/crypto/asn1/asn1_err.c
    M crypto/openssl/crypto/asn1/tasn_dec.c
    M crypto/openssl/crypto/dh/dh.h
    M crypto/openssl/crypto/dh/dh_err.c
    M crypto/openssl/crypto/dh/dh_key.c
    M crypto/openssl/crypto/dsa/dsa.h
    M crypto/openssl/crypto/dsa/dsa_err.c
    M crypto/openssl/crypto/dsa/dsa_ossl.c
    M crypto/openssl/crypto/ocsp/ocsp.h
    M crypto/openssl/crypto/pem/pem.h
    M crypto/openssl/crypto/rsa/rsa.h
    M crypto/openssl/crypto/rsa/rsa_eay.c
    M crypto/openssl/crypto/rsa/rsa_err.c
    M crypto/openssl/crypto/rsa/rsa_sign.c
    M crypto/openssl/ssl/s2_srvr.c
    M crypto/openssl/ssl/s3_lib.c
    M crypto/openssl/ssl/ssltest.c
    M sys/netgraph/NOTES
    M sys/netgraph/bluetooth/drivers/bt3c/ng_bt3c_pccard.c
    M sys/netgraph/netgraph.h
    M sys/netgraph/ng_UI.c
    M sys/netgraph/ng_UI.h
    M sys/netgraph/ng_async.c
    M sys/netgraph/ng_async.h
    M sys/netgraph/ng_atmllc.c
    M sys/netgraph/ng_atmllc.h
    M sys/netgraph/ng_base.c
    M sys/netgraph/ng_bpf.c
    M sys/netgraph/ng_bpf.h
    M sys/netgraph/ng_bridge.c
    M sys/netgraph/ng_bridge.h
    M sys/netgraph/ng_car.c
    M sys/netgraph/ng_car.h
    M sys/netgraph/ng_cisco.c
    M sys/netgraph/ng_cisco.h
    M sys/netgraph/ng_deflate.c
    M sys/netgraph/ng_deflate.h
    M sys/netgraph/ng_device.c
    M sys/netgraph/ng_device.h
    M sys/netgraph/ng_echo.c
    M sys/netgraph/ng_echo.h
    M sys/netgraph/ng_eiface.c
    M sys/netgraph/ng_eiface.h
    M sys/netgraph/ng_etf.c
    M sys/netgraph/ng_etf.h
    M sys/netgraph/ng_ether.c
    M sys/netgraph/ng_ether.h
    M sys/netgraph/ng_fec.c
    M sys/netgraph/ng_fec.h
    M sys/netgraph/ng_frame_relay.c
    M sys/netgraph/ng_frame_relay.h
    M sys/netgraph/ng_gif.c
    M sys/netgraph/ng_gif.h
    M sys/netgraph/ng_gif_demux.c
    M sys/netgraph/ng_gif_demux.h
    M sys/netgraph/ng_hole.c
    M sys/netgraph/ng_hole.h
    M sys/netgraph/ng_hub.c
    M sys/netgraph/ng_hub.h
    M sys/netgraph/ng_iface.c
    M sys/netgraph/ng_iface.h
    M sys/netgraph/ng_ip_input.c
    M sys/netgraph/ng_ip_input.h
    M sys/netgraph/ng_ipfw.c
    M sys/netgraph/ng_ipfw.h
    M sys/netgraph/ng_ksocket.c
    M sys/netgraph/ng_ksocket.h
    M sys/netgraph/ng_l2tp.c
    M sys/netgraph/ng_l2tp.h
    M sys/netgraph/ng_lmi.c
    M sys/netgraph/ng_lmi.h
    M sys/netgraph/ng_message.h
    M sys/netgraph/ng_mppc.c
    M sys/netgraph/ng_mppc.h
    M sys/netgraph/ng_nat.c
    M sys/netgraph/ng_nat.h
    M sys/netgraph/ng_one2many.c
    M sys/netgraph/ng_one2many.h
    M sys/netgraph/ng_parse.c
    M sys/netgraph/ng_parse.h
    M sys/netgraph/ng_ppp.c
    M sys/netgraph/ng_ppp.h
    M sys/netgraph/ng_pppoe.c
    M sys/netgraph/ng_pppoe.h
    M sys/netgraph/ng_pptpgre.c
    M sys/netgraph/ng_pptpgre.h
    M sys/netgraph/ng_pred1.c
    M sys/netgraph/ng_pred1.h
    M sys/netgraph/ng_rfc1490.c
    M sys/netgraph/ng_rfc1490.h
    M sys/netgraph/ng_sample.c
    M sys/netgraph/ng_sample.h
    M sys/netgraph/ng_socket.c
    M sys/netgraph/ng_socket.h
    M sys/netgraph/ng_socketvar.h
    M sys/netgraph/ng_source.c
    M sys/netgraph/ng_source.h
    M sys/netgraph/ng_split.c
    M sys/netgraph/ng_split.h
    M sys/netgraph/ng_sppp.c
    M sys/netgraph/ng_sppp.h
    M sys/netgraph/ng_tag.c
    M sys/netgraph/ng_tag.h
    M sys/netgraph/ng_tcpmss.c
    M sys/netgraph/ng_tcpmss.h
    M sys/netgraph/ng_tee.c
    M sys/netgraph/ng_tee.h
    M sys/netgraph/ng_tty.c
    M sys/netgraph/ng_tty.h
    M sys/netgraph/ng_vjc.c
    M sys/netgraph/ng_vjc.h
    M sys/netgraph/ng_vlan.c
    M sys/netgraph/ng_vlan.h
    M sys/sparc64/include/_bus.h
    M sys/sparc64/include/_inttypes.h
    M sys/sparc64/include/_limits.h
    M sys/sparc64/include/_stdint.h
    M sys/sparc64/include/_types.h
    M sys/sparc64/include/asi.h
    M sys/sparc64/include/asm.h
    M sys/sparc64/include/asmacros.h
    M sys/sparc64/include/atomic.h
    M sys/sparc64/include/bus.h
    M sys/sparc64/include/bus_common.h
    M sys/sparc64/include/bus_dma.h
    M sys/sparc64/include/bus_private.h
    M sys/sparc64/include/cache.h
    M sys/sparc64/include/ccr.h
    M sys/sparc64/include/clock.h
    M sys/sparc64/include/cpu.h
    M sys/sparc64/include/cpufunc.h
    M sys/sparc64/include/db_machdep.h
    M sys/sparc64/include/elf.h
    M sys/sparc64/include/endian.h
    M sys/sparc64/include/exec.h
    M sys/sparc64/include/float.h
    M sys/sparc64/include/floatingpoint.h
    M sys/sparc64/include/fp.h
    M sys/sparc64/include/frame.h
    M sys/sparc64/include/fsr.h
    M sys/sparc64/include/gdb_machdep.h
    M sys/sparc64/include/idprom.h
    M sys/sparc64/include/ieee.h
    M sys/sparc64/include/ieeefp.h
    M sys/sparc64/include/in_cksum.h
    M sys/sparc64/include/instr.h
    M sys/sparc64/include/intr_machdep.h
    M sys/sparc64/include/iommureg.h
    M sys/sparc64/include/iommuvar.h
    M sys/sparc64/include/kdb.h
    M sys/sparc64/include/kerneldump.h
    M sys/sparc64/include/ktr.h
    M sys/sparc64/include/limits.h
    M sys/sparc64/include/lsu.h
    M sys/sparc64/include/md_var.h
    M sys/sparc64/include/memdev.h
    M sys/sparc64/include/metadata.h
    M sys/sparc64/include/ofw_machdep.h
    M sys/sparc64/include/ofw_mem.h
    M sys/sparc64/include/ofw_nexus.h
    M sys/sparc64/include/param.h
    M sys/sparc64/include/pcb.h
    M sys/sparc64/include/pcpu.h
    M sys/sparc64/include/pmap.h
    M sys/sparc64/include/pmc_mdep.h
    M sys/sparc64/include/proc.h
    M sys/sparc64/include/profile.h
    M sys/sparc64/include/pstate.h
    M sys/sparc64/include/ptrace.h
    M sys/sparc64/include/reg.h
    M sys/sparc64/include/reloc.h
    M sys/sparc64/include/resource.h
    M sys/sparc64/include/runq.h
    M sys/sparc64/include/sc_machdep.h
    M sys/sparc64/include/setjmp.h
    M sys/sparc64/include/sf_buf.h
    M sys/sparc64/include/sigframe.h
    M sys/sparc64/include/signal.h
    M sys/sparc64/include/smp.h
    M sys/sparc64/include/stack.h
    M sys/sparc64/include/stdarg.h
    M sys/sparc64/include/sysarch.h
    M sys/sparc64/include/tick.h
    M sys/sparc64/include/tlb.h
    M sys/sparc64/include/trap.h
    M sys/sparc64/include/tsb.h
    M sys/sparc64/include/tstate.h
    M sys/sparc64/include/tte.h
    M sys/sparc64/include/ucontext.h
    M sys/sparc64/include/upa.h
    M sys/sparc64/include/utrap.h
    M sys/sparc64/include/varargs.h
    M sys/sparc64/include/ver.h
    M sys/sparc64/include/vmparam.h
    M sys/sparc64/include/watch.h
    M sys/sparc64/include/wstate.h
    M sys/sparc64/isa/isa.c
    M sys/sparc64/isa/isa_dma.c
    M sys/sparc64/isa/ofw_isa.c
    M sys/sparc64/isa/ofw_isa.h
    M sys/sparc64/pci/apb.c
    M sys/sparc64/pci/ofw_pci.h
    M sys/sparc64/pci/ofw_pcib.c
    M sys/sparc64/pci/ofw_pcib_subr.c
    M sys/sparc64/pci/ofw_pcib_subr.h
    M sys/sparc64/pci/ofw_pcibus.c
    M sys/sparc64/pci/psycho.c
    M sys/sparc64/pci/psychoreg.h
    M sys/sparc64/pci/psychovar.h
    M sys/sparc64/sbus/dma_sbus.c
    M sys/sparc64/sbus/lsi64854.c
    M sys/sparc64/sbus/lsi64854reg.h
    M sys/sparc64/sbus/lsi64854var.h
    M sys/sparc64/sbus/ofw_sbus.h
    M sys/sparc64/sbus/sbus.c
    M sys/sparc64/sbus/sbusreg.h
    M sys/sparc64/sbus/sbusvar.h

  Log Message:
  -----------
  This commit was manufactured by cvs2svn to create branch 'RELENG_0_4'.


  Commit: 93edd549ecbf997f5520a67b7262cc369ed15048
      https://github.com/MidnightBSD/src/commit/93edd549ecbf997f5520a67b7262cc369ed15048
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-12 (Wed, 12 Jun 2013)

  Changed paths:
    M sys/conf/newvers.sh

  Log Message:
  -----------
  0.4 is now prerelease


  Commit: 627501903592244c34af4060c2f95ed7480a3041
      https://github.com/MidnightBSD/src/commit/627501903592244c34af4060c2f95ed7480a3041
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-12 (Wed, 12 Jun 2013)

  Changed paths:
    M sys/sys/param.h

  Log Message:
  -----------
  bump midnightbsd version after prerelease bump


  Commit: 18b45d8faa27db958debf3f74863e34f9f3e2f75
      https://github.com/MidnightBSD/src/commit/18b45d8faa27db958debf3f74863e34f9f3e2f75
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-14 (Fri, 14 Jun 2013)

  Changed paths:
    M UPDATING

  Log Message:
  -----------
  Signify the branch was created here. We're on prerelease now.


  Commit: ca746354e59f62644fe40cc160885ca511304c46
      https://github.com/MidnightBSD/src/commit/ca746354e59f62644fe40cc160885ca511304c46
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-14 (Fri, 14 Jun 2013)

  Changed paths:
    M ObsoleteFiles.inc

  Log Message:
  -----------
  Remove additional old files


  Commit: bb92613c78f98455c01619edb995064e57deabc1
      https://github.com/MidnightBSD/src/commit/bb92613c78f98455c01619edb995064e57deabc1
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-16 (Sun, 16 Jun 2013)

  Changed paths:
    M lib/libusb/Makefile
    M lib/libusb/libusb20.c
    M lib/libusb/libusb20_ugen20.c

  Log Message:
  -----------
  rebrand


  Commit: 21f4704193aa79a1d099d58cbbe1343e98e1b3d9
      https://github.com/MidnightBSD/src/commit/21f4704193aa79a1d099d58cbbe1343e98e1b3d9
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-18 (Tue, 18 Jun 2013)

  Changed paths:
    M sys/vm/vm_map.c

  Log Message:
  -----------
  Due to insufficient permission checks in the virtual memory system, a
tracing process (such as a debugger) may be able to modify portions of
the traced process's address space to which the traced process itself
does not have write access.

This error can be exploited to allow unauthorized modification of an
arbitrary file to which the attacker has read access, but not write
access.  Depending on the file and the nature of the modifications,
this can result in privilege escalation.

To exploit this vulnerability, an attacker must be able to run
arbitrary code with user privileges on the target system.

Obtained from: FreeBSD


  Commit: 2ebd04557a564481b154b312572a943aba2ec4d1
      https://github.com/MidnightBSD/src/commit/2ebd04557a564481b154b312572a943aba2ec4d1
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-21 (Fri, 21 Jun 2013)

  Changed paths:
    M lib/libc/gen/getosreldate.3

  Log Message:
  -----------
  fix regression


  Commit: 1e514aeda0f9b29d99dce1228599c7290278c43d
      https://github.com/MidnightBSD/src/commit/1e514aeda0f9b29d99dce1228599c7290278c43d
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-06-21 (Fri, 21 Jun 2013)

  Changed paths:
    M lib/libc/gen/getosreldate.3

  Log Message:
  -----------
  fix branding missed in the last commit


  Commit: f1cd49679a6056dd3dfecc09b3165c0f71eab698
      https://github.com/MidnightBSD/src/commit/f1cd49679a6056dd3dfecc09b3165c0f71eab698
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-03 (Wed, 03 Jul 2013)

  Changed paths:
    M sys/dev/fxp/if_fxp.c

  Log Message:
  -----------
  dhclient will misinterpret the down/up cycle of fxp during init incorrectly and try to reconfigure the interface.


  Commit: 07ea1301973e895e957f57fb1237871e0baa1c7e
      https://github.com/MidnightBSD/src/commit/07ea1301973e895e957f57fb1237871e0baa1c7e
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-03 (Wed, 03 Jul 2013)

  Changed paths:
    M sys/modules/ntfs/Makefile

  Log Message:
  -----------
  tag


  Commit: c77d541c581afe746548ad7cab9190310d1a7624
      https://github.com/MidnightBSD/src/commit/c77d541c581afe746548ad7cab9190310d1a7624
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-04 (Thu, 04 Jul 2013)

  Changed paths:
    M sys/conf/newvers.sh
    M sys/sys/param.h

  Log Message:
  -----------
  prepare for 0.4-RELEASE


  Commit: 1ead18f52d209ce3cf78c0ece3b7f7becb258388
      https://github.com/MidnightBSD/src/commit/1ead18f52d209ce3cf78c0ece3b7f7becb258388
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-04 (Thu, 04 Jul 2013)

  Changed paths:
    M UPDATING

  Log Message:
  -----------
  add release note


  Commit: 8d895e4551b78911d3a3bf185bf26fcaaa5c57ce
      https://github.com/MidnightBSD/src/commit/8d895e4551b78911d3a3bf185bf26fcaaa5c57ce
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-17 (Wed, 17 Jul 2013)

  Changed paths:
    M lib/libmport/install.c
    M lib/libmport/verify.c

  Log Message:
  -----------
  wrong parameter.


  Commit: 8c0d99bfcfb78a16a3c4fafbfdc4cbdb42c2d929
      https://github.com/MidnightBSD/src/commit/8c0d99bfcfb78a16a3c4fafbfdc4cbdb42c2d929
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-18 (Thu, 18 Jul 2013)

  Changed paths:
    M UPDATING

  Log Message:
  -----------
  Document libmport patch


  Commit: 344b23ff38595b0ccb070a7d06683af4250f1ca9
      https://github.com/MidnightBSD/src/commit/344b23ff38595b0ccb070a7d06683af4250f1ca9
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-28 (Sun, 28 Jul 2013)

  Changed paths:
    M contrib/bind98/lib/dns/rdata/generic/keydata_65533.c

  Log Message:
  -----------
  BIND can crash on invalid rdata.


  Commit: 677a028590ff2bfa54969273402cd3d091b4811c
      https://github.com/MidnightBSD/src/commit/677a028590ff2bfa54969273402cd3d091b4811c
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-07-28 (Sun, 28 Jul 2013)

  Changed paths:
    M sys/kern/vfs_export.c

  Log Message:
  -----------
  Fix a vulnerability in nfs server where incorrect credentials can be used to access a file.


  Commit: 41d1125a9c48d8a0347a2614d9d21199d8112da2
      https://github.com/MidnightBSD/src/commit/41d1125a9c48d8a0347a2614d9d21199d8112da2
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-08-01 (Thu, 01 Aug 2013)

  Changed paths:
    M sys/conf/newvers.sh

  Log Message:
  -----------
  bump to p1 to cover the recent security issues.

Long term plan is to stop using p1, p2, p3, ... and increment release version like NetBSD does, but we'll "announce" that before making the change.


  Commit: cd0a7d68456a79ac66ea41180ee55ecfd7109e3a
      https://github.com/MidnightBSD/src/commit/cd0a7d68456a79ac66ea41180ee55ecfd7109e3a
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-08-17 (Sat, 17 Aug 2013)

  Changed paths:
    M lib/libmport/install.c
    M lib/libmport/util.c

  Log Message:
  -----------
  Thought I already fixed this, but correct the hash verify routine.


  Commit: 3e820f8be5738509b45ccee6be9ad8a2ee934775
      https://github.com/MidnightBSD/src/commit/3e820f8be5738509b45ccee6be9ad8a2ee934775
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-08-22 (Thu, 22 Aug 2013)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/netinet/in_mcast.c
    M sys/netinet/sctp_output.c
    M sys/netinet6/in6_mcast.c

  Log Message:
  -----------
  0.4-RELEASE-p2

Fix two security vulnerabilities.

Fix an integer overflow in IP_MSFILTER (IP MULTICAST). This could be exploited to read memory by a user process.

When initializing the SCTP state cookie being sent in INIT-ACK chunks,
a buffer allocated from the kernel stack is not completely initialized.

Patches obtained from: FreeBSD


  Commit: e217b381d934e4ff7240688cb3e8860354ce0108
      https://github.com/MidnightBSD/src/commit/e217b381d934e4ff7240688cb3e8860354ce0108
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-08-25 (Sun, 25 Aug 2013)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/contrib/altq/altq/altq_cbq.c
    M sys/contrib/altq/altq/altq_cdnr.c
    M sys/contrib/altq/altq/altq_hfsc.c
    M sys/contrib/altq/altq/altq_priq.c
    M sys/contrib/altq/altq/altq_red.c
    M sys/contrib/altq/altq/altq_rio.c
    M sys/contrib/altq/altq/altq_subr.c

  Log Message:
  -----------
  0.4-RELEASE-p3

Fix the broken altq that was part of the release.


  Commit: b91e66d90a2fbfc038274ac6d3e96ab88004b0bb
      https://github.com/MidnightBSD/src/commit/b91e66d90a2fbfc038274ac6d3e96ab88004b0bb
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-09-10 (Tue, 10 Sep 2013)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/fs/nullfs/null_vnops.c
    M sys/net/if.c
    M sys/netinet6/in6.c
    M sys/netnatm/natm.c

  Log Message:
  -----------
          0.4-RELEASE-p3

        nullfs(5)

        The nullfs(5) implementation of the VOP_LINK(9) VFS operation does not
        check whether the source and target of the link are both in the same
        nullfs instance.  It is therefore possible to create a hardlink from a
        location in one nullfs instance to a file in another, as long as the
        underlying (source) filesystem is the same.

        ifioctl

        As is commonly the case, the IPv6 and ATM network layer ioctl request
        handlers are written in such a way that an unrecognized request is
        passed on unmodified to the link layer, which will either handle it or
        return an error code.

        Network interface drivers, however, assume that the SIOCSIFADDR,
        SIOCSIFBRDADDR, SIOCSIFDSTADDR and SIOCSIFNETMASK requests have been
        handled at the network layer, and therefore do not perform input
        validation or verify the caller's credentials.  Typical link-layer
        actions for these requests may include marking the interface as "up"
        and resetting the underlying hardware.


  Commit: 7b05a0e81a52d1a59f66fa4d9a9e4e9e01791a0a
      https://github.com/MidnightBSD/src/commit/7b05a0e81a52d1a59f66fa4d9a9e4e9e01791a0a
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-11-29 (Fri, 29 Nov 2013)

  Changed paths:
    M UPDATING
    M lib/libc/iconv/citrus_iconv.c
    M sys/conf/newvers.sh

  Log Message:
  -----------
  Implement a compatibility fix for libc's iconv support to work with gettext and other GNU packages.

MidnightBSD 0.4-RELEASE-p5


  Commit: 5ca1101ad661f2a95ba47e70c4d2955a4821e72f
      https://github.com/MidnightBSD/src/commit/5ca1101ad661f2a95ba47e70c4d2955a4821e72f
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2013-11-30 (Sat, 30 Nov 2013)

  Changed paths:

  Log Message:
  -----------
  Move RELENG_0_4 to stable/0.4


  Commit: 200f6cc2c0586c2242ce24b536354d880f56edda
      https://github.com/MidnightBSD/src/commit/200f6cc2c0586c2242ce24b536354d880f56edda
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-01-15 (Wed, 15 Jan 2014)

  Changed paths:
    M UPDATING
    M contrib/bind98/bin/named/query.c
    M contrib/bsnmp/lib/snmpagent.c
    M sys/conf/newvers.sh

  Log Message:
  -----------
  security update


  Commit: 7807340216289f9b65557674d51b05b969a32907
      https://github.com/MidnightBSD/src/commit/7807340216289f9b65557674d51b05b969a32907
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-02-01 (Sat, 01 Feb 2014)

  Changed paths:
    M share/skel/dot.profile

  Log Message:
  -----------
  -s flag missing from ssh-agent on startup. this causes a lot of duplicate ssh-agent


  Commit: bef3115421054712b8591e6cbd3518532ddbacac
      https://github.com/MidnightBSD/src/commit/bef3115421054712b8591e6cbd3518532ddbacac
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-02-01 (Sat, 01 Feb 2014)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh

  Log Message:
  -----------
  document dot.profile fix.


  Commit: dd118cd8f7a9347a49a3cc4a3726f2bbc5dc2bf9
      https://github.com/MidnightBSD/src/commit/dd118cd8f7a9347a49a3cc4a3726f2bbc5dc2bf9
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-03-08 (Sat, 08 Mar 2014)

  Changed paths:

  Log Message:
  -----------
  remove cvs2svn:cvs-rev prop


  Commit: ae77b17a1a631403d3fe42d6338481f7dd460c33
      https://github.com/MidnightBSD/src/commit/ae77b17a1a631403d3fe42d6338481f7dd460c33
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-04-09 (Wed, 09 Apr 2014)

  Changed paths:
    M crypto/openssl/crypto/bn/bn.h
    M crypto/openssl/crypto/bn/bn_lib.c
    M crypto/openssl/crypto/ec/ec2_mult.c

  Log Message:
  -----------
  Fix CVE-2014-0076 in OpenSSL


  Commit: 7858bdc7a7955137794619342cd4cd49943942c1
      https://github.com/MidnightBSD/src/commit/7858bdc7a7955137794619342cd4cd49943942c1
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-04-09 (Wed, 09 Apr 2014)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh

  Log Message:
  -----------
  0.4-p8 openssl fix.


  Commit: e861962e87f905bad0c1107536e9c35d4c8c781c
      https://github.com/MidnightBSD/src/commit/e861962e87f905bad0c1107536e9c35d4c8c781c
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-04-09 (Wed, 09 Apr 2014)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/fs/nfsserver/nfs_nfsdserv.c

  Log Message:
  -----------
  0.4-RELEASE-p9

Fix a security issue affecting NFS server where a trusted client can deadlock the server.


  Commit: a405c93dbfd1c6c04bfc0560530bc4bc2a0bb4f4
      https://github.com/MidnightBSD/src/commit/a405c93dbfd1c6c04bfc0560530bc4bc2a0bb4f4
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-04-30 (Wed, 30 Apr 2014)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/netinet/tcp_reass.c

  Log Message:
  -----------
  MidnightBSD 0.4-RELEASE-p10

        Fix a TCP reassembly bug that could result in a DOS attack
        of the system. It may be possible to obtain portions
        of kernel memory as well.


  Commit: 500e9b21c99cb811ae5ba66e375f420f38064eaf
      https://github.com/MidnightBSD/src/commit/500e9b21c99cb811ae5ba66e375f420f38064eaf
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-06-04 (Wed, 04 Jun 2014)

  Changed paths:
    M UPDATING
    M contrib/sendmail/src/conf.c
    M sys/conf/newvers.sh
    M sys/kern/kern_ktrace.c

  Log Message:
  -----------
  MidnightBSD 0.4-RELEASE-p11

Security updates for sendmail and ktrace.  See UPDATING.


  Commit: 67acf2fd53da8e51d549650797a6f375829db57b
      https://github.com/MidnightBSD/src/commit/67acf2fd53da8e51d549650797a6f375829db57b
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-06-06 (Fri, 06 Jun 2014)

  Changed paths:
    M UPDATING
    M crypto/openssl/ssl/d1_both.c
    M crypto/openssl/ssl/s3_clnt.c
    M crypto/openssl/ssl/s3_pkt.c
    M crypto/openssl/ssl/s3_srvr.c
    M crypto/openssl/ssl/ssl3.h
    M sys/conf/newvers.sh

  Log Message:
  -----------
  MidnightBSD 0.4-RELEASE-p12


  Commit: b0b72081b4b59cb6c4403da229fe84d391ce6305
      https://github.com/MidnightBSD/src/commit/b0b72081b4b59cb6c4403da229fe84d391ce6305
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-07-10 (Thu, 10 Jul 2014)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/kern/uipc_sockbuf.c
    M sys/netinet/sctp_auth.c
    M sys/netinet/sctp_indata.c
    M sys/netinet/sctputil.c

  Log Message:
  -----------
  MidnightBSD 0.4-RELEASE-p13  Fix a vulnerability in the control message API. A buffer is not properly cleared.


  Commit: 9e7085e7edd0a847e8f6d53d225497b3fc23831e
      https://github.com/MidnightBSD/src/commit/9e7085e7edd0a847e8f6d53d225497b3fc23831e
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-09-03 (Wed, 03 Sep 2014)

  Changed paths:

  Log Message:
  -----------
  drop cvs2svn prop


  Commit: f0ae3ed8bd4b0cc7e0ca35c41d902df02514e72d
      https://github.com/MidnightBSD/src/commit/f0ae3ed8bd4b0cc7e0ca35c41d902df02514e72d
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-09-09 (Tue, 09 Sep 2014)

  Changed paths:
    M UPDATING
    M crypto/openssl/crypto/asn1/a_object.c
    M crypto/openssl/crypto/objects/obj_dat.c
    M crypto/openssl/ssl/d1_both.c
    M crypto/openssl/ssl/d1_clnt.c
    M crypto/openssl/ssl/s23_srvr.c
    M crypto/openssl/ssl/s3_clnt.c
    M sys/conf/newvers.sh

  Log Message:
  -----------
  0.4-RELEASE-p14

OpenSSL security patch:

        The receipt of a specifically crafted DTLS handshake message may cause OpenSSL
        to consume large amounts of memory. [CVE-2014-3506]

        The receipt of a specifically crafted DTLS packet could cause OpenSSL to leak
        memory. [CVE-2014-3507]

        A flaw in OBJ_obj2txt may cause pretty printing functions such as
        X509_name_oneline, X509_name_print_ex et al. to leak some information from
        the stack. [CVE-2014-3508]

        OpenSSL DTLS clients enabling anonymous (EC)DH ciphersuites are subject to
        a denial of service attack. [CVE-2014-3510]


  Commit: 58d66678fff7c09148c2622b1890e8c177b24193
      https://github.com/MidnightBSD/src/commit/58d66678fff7c09148c2622b1890e8c177b24193
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2014-09-16 (Tue, 16 Sep 2014)

  Changed paths:
    M UPDATING
    M sys/conf/newvers.sh
    M sys/netinet/tcp_input.c

  Log Message:
  -----------
  0.4-RELEASE-p15

20140916:
        Fix a security issue with TCP SYN.

        When a segment with the SYN flag for an already existing connection arrives,
        the TCP stack tears down the connection, bypassing a check that the
        sequence number in the segment is in the expected window.


Compare: https://github.com/MidnightBSD/src/compare/794f8404f9d2%5E...58d66678fff7


More information about the Midnightbsd-cvs mailing list