S.P.Zeidler | 5 Nov 2010 10:36
Picon

Planned outage of mail.netbsd.org

Dear all,

please be advised that mail.NetBSD.org will not be available 
for a few hours Sunday Nov 7th starting 9:00 UTC.
It's upgrade-time. :)

best regards,
	spz

Soren Jacobsen | 19 Nov 2010 10:56
Picon

NetBSD 5.1

On behalf of the NetBSD developers, I am pleased to announce that NetBSD
5.1 is available for download.  NetBSD 5.1 is the first feature update
of the NetBSD 5.0 release branch.  It includes security and bug fixes,
as well as improved hardware support and new features.

Some highlights include:
- RAIDframe parity maps, which greatly improve parity rewrite times
  after unclean shutdown
- X.Org updates
- Support for many more network devices
- Xen PAE dom0 support
- Xen PCI pass-through support

For full details, please see the release notes at:

    http://www.NetBSD.org/releases/formal-5/NetBSD-5.1.html

ISO and USB images can be downloaded using BitTorrent, and we encourage
users who wish to install via ISO/USB images to take advantage of this,
as the images are very well seeded.

    http://www.NetBSD.org/mirrors/torrents/

Complete source and binaries for NetBSD 5.1 are available for download
at many sites around the world. A list of download sites providing FTP,
AnonCVS, and other services may be found at:

    http://www.NetBSD.org/mirrors/

========================================================================
(Continue reading)

NetBSD Security Officer | 29 Nov 2010 16:55
Picon

NetBSD Security Advisory 2010-012: OpenSSL TLS extension parsing race condition


		 NetBSD Security Advisory 2010-012
		 =================================

Topic:		OpenSSL TLS extension parsing race condition.

Version:	NetBSD-current:		source prior to November 18, 2010
		NetBSD 5.0.*:		affected
		NetBSD 5.0:		affected
		NetBSD 5.1:		affected
		NetBSD 4.0.*:		not affected
		NetBSD 4.0:		not affected
		pkgsrc:			openssl package prior to 0.9.8p

Severity:	Denial of Service and potential arbitrary code execution

Fixed:		NetBSD-current:		November 17, 2010
		NetBSD-5-0 branch:	November 19, 2010
		NetBSD-5-1 branch:	November 19, 2010
		NetBSD-5 branch:	November 19, 2010
		pkgsrc 2010Q3:		openssl-0.9.8p corrects this issue

Please note that NetBSD releases prior to 4.0 are no longer supported.
It is recommended that all users upgrade to a supported release.

Abstract
========

A flaw has been found in the OpenSSL TLS server extension code parsing which
on affected servers can be exploited in a buffer overrun attack.
(Continue reading)

NetBSD Security Officer | 29 Nov 2010 16:56
Picon

NetBSD Security Advisory 2010-013: UDP6 Option Parsing local Denial of Service


		 NetBSD Security Advisory 2010-013
		 =================================

Topic:		UDP6 Option Parsing local Denial of Service

Version:	NetBSD-current:		affected prior to Jul 15, 2010
		NetBSD 5.1:		not affected
		NetBSD 5.0.*:		affected
		NetBSD 5.0:		affected
		NetBSD 4.0.*:		affected
		NetBSD 4.0:		affected

Severity:	Local system crash

Fixed:		NetBSD-current:		Jul 15, 2010
		NetBSD-5-0 branch:	Jul 16, 2010
		NetBSD-5 branch:	Jul 16, 2010 (5.1 includes the fix)
		NetBSD-4-0 branch:	Jul 16, 2010
		NetBSD-4 branch:	Jul 16, 2010

Please note that NetBSD releases prior to 4.0 are no longer supported.
It is recommended that all users upgrade to a supported release.

Abstract
========

The udp6_output() routing did not do proper variable management
allowing an attacker to crash a local system by sending an UDP6
datagram with suitable parameters.
(Continue reading)


Gmane