Picon
Favicon

FreeBSD Security Advisory FreeBSD-SA-12:01.openssl


=============================================================================
FreeBSD-SA-12:01.openssl                                    Security Advisory
                                                          The FreeBSD Project

Topic:          OpenSSL multiple vulnerabilities

Category:       contrib
Module:         openssl
Announced:      2012-05-03
Credits:        Adam Langley, George Kadianakis, Ben Laurie,
                Ivan Nestlerode, Tavis Ormandy
Affects:        All supported versions of FreeBSD.
Corrected:      2012-05-03 15:25:11 UTC (RELENG_7, 7.4-STABLE)
                2012-05-03 15:25:11 UTC (RELENG_7_4, 7.4-RELEASE-p7)
                2012-05-03 15:25:11 UTC (RELENG_8, 8.3-STABLE)
                2012-05-03 15:25:11 UTC (RELENG_8_3, 8.3-RELEASE-p1)
                2012-05-03 15:25:11 UTC (RELENG_8_2, 8.2-RELEASE-p7)
                2012-05-03 15:25:11 UTC (RELENG_8_1, 8.1-RELEASE-p9)
                2012-05-03 15:25:11 UTC (RELENG_9, 9.0-STABLE)
                2012-05-03 15:25:11 UTC (RELENG_9_0, 9.0-RELEASE-p1)
CVE Name:       CVE-2011-4576, CVE-2011-4619, CVE-2011-4109,
                CVE-2012-0884, CVE-2012-2110

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:http://security.FreeBSD.org/>.

I.   Background

(Continue reading)

Daniel Gerzo | 12 May 2012 23:39
Picon
Favicon

FreeBSD Quarterly Status Report January-March, 2012

FreeBSD Quarterly Status Report January-March, 2012

Introduction

   This report covers FreeBSD-related projects between January and March
   2012. It is the first of the four reports planned for 2012. This
   quarter was highlighted by releasing the next major version of FreeBSD,
   9.0, which was finally released in the beginning of January 2012. The
   FreeBSD Project dedicates the FreeBSD 9.0-RELEASE to the memory of
   Dennis M. Ritchie, one of the founding fathers of the UNIXŽ operating
   system. Our release engineering team has been also busy with
   preparation of the 8.3-RELEASE, which was publicly announced in April.

   Thanks to all the reporters for the excellent work! This report
   contains 27 entries and we hope you enjoy reading it.

   Please note that the deadline for submissions covering the period
   between April and June 2012 is July 15th, 2012.
     __________________________________________________________________

Projects

     * FreeBSD Services Control
     * GNU-Free C++11 Stack
     * Growing filesystems online
     * The FreeNAS Project

User-land Programs

     * Clang Replacing GCC in the Base System
(Continue reading)

FreeBSD Security Advisories | 30 May 2012 14:47
Picon
Favicon

FreeBSD Security Advisory FreeBSD-SA-12:01.openssl


=============================================================================
FreeBSD-SA-12:01.openssl                                    Security Advisory
                                                          The FreeBSD Project

Topic:          OpenSSL multiple vulnerabilities

Category:       contrib
Module:         openssl
Announced:      2012-05-03
Credits:        Adam Langley, George Kadianakis, Ben Laurie,
                Ivan Nestlerode, Tavis Ormandy
Affects:        All supported versions of FreeBSD.
Corrected:      2012-05-30 12:01:28 UTC (RELENG_7, 7.4-STABLE)
                2012-05-30 12:01:28 UTC (RELENG_7_4, 7.4-RELEASE-p8)
                2012-05-30 12:01:28 UTC (RELENG_8, 8.3-STABLE)
                2012-05-30 12:01:28 UTC (RELENG_8_3, 8.3-RELEASE-p2)
                2012-05-30 12:01:28 UTC (RELENG_8_2, 8.2-RELEASE-p8)
                2012-05-30 12:01:28 UTC (RELENG_8_1, 8.1-RELEASE-p10)
                2012-05-30 12:01:28 UTC (RELENG_9, 9.0-STABLE)
                2012-05-30 12:01:28 UTC (RELENG_9_0, 9.0-RELEASE-p2)
CVE Name:       CVE-2011-4576, CVE-2011-4619, CVE-2011-4109,
                CVE-2012-0884, CVE-2012-2110

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:http://security.FreeBSD.org/>.

0.   Revision History

(Continue reading)

FreeBSD Security Advisories | 30 May 2012 14:47
Picon
Favicon

FreeBSD Security Advisory FreeBSD-SA-12:02.crypt


=============================================================================
FreeBSD-SA-12:02.crypt                                      Security Advisory
                                                          The FreeBSD Project

Topic:          Incorrect crypt() hashing

Category:       core
Module:         libcrypt
Announced:      2012-05-30
Credits:        Rubin Xu, Joseph Bonneau, Donting Yu
Affects:        All supported versions of FreeBSD.
Corrected:      2012-05-30 12:01:28 UTC (RELENG_7, 7.4-STABLE)
                2012-05-30 12:01:28 UTC (RELENG_7_4, 7.4-RELEASE-p8)
                2012-05-30 12:01:28 UTC (RELENG_8, 8.3-STABLE)
                2012-05-30 12:01:28 UTC (RELENG_8_3, 8.3-RELEASE-p2)
                2012-05-30 12:01:28 UTC (RELENG_8_2, 8.2-RELEASE-p8)
                2012-05-30 12:01:28 UTC (RELENG_8_1, 8.1-RELEASE-p10)
                2012-05-30 12:01:28 UTC (RELENG_9, 9.0-STABLE)
                2012-05-30 12:01:28 UTC (RELENG_9_0, 9.0-RELEASE-p2)
CVE Name:       CVE-2012-2143

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:http://security.FreeBSD.org/>.

I.   Background

The crypt(3) function performs password hashing with additional code added
to deter key search attempts.
(Continue reading)


Gmane