Friday, February 24, 2017

[CentOS-announce] CEBA-2017:0302 CentOS 6 ding-libs BugFix Update

CentOS Errata and Bugfix Advisory 2017:0302

Upstream details at : https://rhn.redhat.com/errata/RHBA-2017-0302.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
6b6b750c5843f85219890391c805bf2dee76e254549abf23978aad260571f7e9 libbasicobjects-0.1.1-11.el6_8.1.i686.rpm
3f8b660e3a9e8dd1940d4f353234cc096e51da9bf5b00e4f2ebb4a4793036dc0 libbasicobjects-devel-0.1.1-11.el6_8.1.i686.rpm
f296af090230380058a024a45887cee1844ef71f8277fb408302d62bd17fce0c libcollection-0.6.2-11.el6_8.1.i686.rpm
f24a2807b8f91805859a069f82a0f5aea58599ab70fbe4087532642e26cf781d libcollection-devel-0.6.2-11.el6_8.1.i686.rpm
d930824e4f58ed9bd1aa10c677280cfb0bb758cb1d9687c3799ac28b9435dd18 libdhash-0.4.3-11.el6_8.1.i686.rpm
3f755c2dce44561d1ff5ab8c0b9762ca452441dc8e1a1bd354a4efb0b5281b7f libdhash-devel-0.4.3-11.el6_8.1.i686.rpm
9abef3517282f4dfb6330a43cf1692225bec055a56cedc7cad2785a8b4ddd14f libini_config-1.1.0-11.el6_8.1.i686.rpm
cbf1f9462a9f6e009f42517178c70f57b237bd73cd925deeae70da3777756ab0 libini_config-devel-1.1.0-11.el6_8.1.i686.rpm
ccf03900c90580479a5de765fcee16fcdc6a7298c56dbe2bab316ee203754375 libpath_utils-0.2.1-11.el6_8.1.i686.rpm
e8f27f432bd68ca84f2c708018d056c69c71324d089501e4b5e0c4ba9aeae892 libpath_utils-devel-0.2.1-11.el6_8.1.i686.rpm
623f8220facbef9545985aa581b70ac347062a8a7a985f4df6faef014e9a04aa libref_array-0.1.4-11.el6_8.1.i686.rpm
7ce1122ced92b0374cb0943c252cefce796d9734901bee22dd084c41f1ed488f libref_array-devel-0.1.4-11.el6_8.1.i686.rpm

x86_64:
6b6b750c5843f85219890391c805bf2dee76e254549abf23978aad260571f7e9 libbasicobjects-0.1.1-11.el6_8.1.i686.rpm
531b6cd8b4bb10cce6e3a8a70acbdbc0ea3f03a374451ec558ac462460c1aaf2 libbasicobjects-0.1.1-11.el6_8.1.x86_64.rpm
3f8b660e3a9e8dd1940d4f353234cc096e51da9bf5b00e4f2ebb4a4793036dc0 libbasicobjects-devel-0.1.1-11.el6_8.1.i686.rpm
3f32973123fed2a557c63e0d7a69b0cf832391b88d0eb5d508b40bcb7f173655 libbasicobjects-devel-0.1.1-11.el6_8.1.x86_64.rpm
f296af090230380058a024a45887cee1844ef71f8277fb408302d62bd17fce0c libcollection-0.6.2-11.el6_8.1.i686.rpm
5d14203de5b0fed0bee28b6f9bf9ff0b6b977d390d5e37d0ef7b0e7d919e8ff3 libcollection-0.6.2-11.el6_8.1.x86_64.rpm
f24a2807b8f91805859a069f82a0f5aea58599ab70fbe4087532642e26cf781d libcollection-devel-0.6.2-11.el6_8.1.i686.rpm
e0ff79df8a23947e32005b63d2fdc47848295a500ea7b1e60fcf1abb2ea95af6 libcollection-devel-0.6.2-11.el6_8.1.x86_64.rpm
d930824e4f58ed9bd1aa10c677280cfb0bb758cb1d9687c3799ac28b9435dd18 libdhash-0.4.3-11.el6_8.1.i686.rpm
e14af19955db45aeed7dffef1d39eaea33937bb4f184a32bdd2b9e6a989ff92a libdhash-0.4.3-11.el6_8.1.x86_64.rpm
3f755c2dce44561d1ff5ab8c0b9762ca452441dc8e1a1bd354a4efb0b5281b7f libdhash-devel-0.4.3-11.el6_8.1.i686.rpm
b947cd7fd8b5a8a2e5acf417d4a7f9537b5048aa7c15d3efcf06acdb48411263 libdhash-devel-0.4.3-11.el6_8.1.x86_64.rpm
9abef3517282f4dfb6330a43cf1692225bec055a56cedc7cad2785a8b4ddd14f libini_config-1.1.0-11.el6_8.1.i686.rpm
551aac4a221590aa7b4cfd9c1ec00aeede52834f4502d3f19ca5df494e5d651b libini_config-1.1.0-11.el6_8.1.x86_64.rpm
cbf1f9462a9f6e009f42517178c70f57b237bd73cd925deeae70da3777756ab0 libini_config-devel-1.1.0-11.el6_8.1.i686.rpm
3d7c807be17a743ad32fd26e717c0d56b0d0b450f379fc3db8a38e212f6b34f6 libini_config-devel-1.1.0-11.el6_8.1.x86_64.rpm
ccf03900c90580479a5de765fcee16fcdc6a7298c56dbe2bab316ee203754375 libpath_utils-0.2.1-11.el6_8.1.i686.rpm
cb0ab65b281ebf272916209c57eaec3fec43aff12f1b20bd24091767ccf165a1 libpath_utils-0.2.1-11.el6_8.1.x86_64.rpm
e8f27f432bd68ca84f2c708018d056c69c71324d089501e4b5e0c4ba9aeae892 libpath_utils-devel-0.2.1-11.el6_8.1.i686.rpm
7e4a5c5416b9bbf238aa3202639bd623ac627dee41fa2542c3d67e2fd3cdc3c3 libpath_utils-devel-0.2.1-11.el6_8.1.x86_64.rpm
623f8220facbef9545985aa581b70ac347062a8a7a985f4df6faef014e9a04aa libref_array-0.1.4-11.el6_8.1.i686.rpm
766feae13356a0cff88a2763164a968e118bcd4f03706e96605f77ed09669565 libref_array-0.1.4-11.el6_8.1.x86_64.rpm
7ce1122ced92b0374cb0943c252cefce796d9734901bee22dd084c41f1ed488f libref_array-devel-0.1.4-11.el6_8.1.i686.rpm
a5a185848a6551acdca74f4ad97e2f34f33a539b5c2e310519f6fea5d52ad6b1 libref_array-devel-0.1.4-11.el6_8.1.x86_64.rpm

Source:
d256d1ce71b8300c87a579fb78fa30db184ff891a66090defce4f657a81c3e7b ding-libs-0.4.0-11.el6_8.1.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2017:0307 Moderate CentOS 6 kernel Security Update

CentOS Errata and Security Advisory 2017:0307 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0307.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
4b19afbec2ec90db7ab39adb3b3caa40d0ce9d49897b613bdd20e77714f1be21 kernel-2.6.32-642.15.1.el6.i686.rpm
c784e1a7a1339f05c0d0df7fe6bac6fbb0b7a480a1af6ad24116a41b98e38eb6 kernel-abi-whitelists-2.6.32-642.15.1.el6.noarch.rpm
2b8e6351259af887492c593fd5f608983fa79f9c84fe2023456493d389b9dc41 kernel-debug-2.6.32-642.15.1.el6.i686.rpm
db434c849f711e6800b56bf3ddc4f77c71a67648e14ec149733bd8b2527d65ca kernel-debug-devel-2.6.32-642.15.1.el6.i686.rpm
0c6a706bbf6b167be4fecf464291ebfbc01d1b4981f55e43a8ed74dd32b8fb11 kernel-devel-2.6.32-642.15.1.el6.i686.rpm
118d0af31dc23edff429fbeeadc65e9d13bd5e639a2b0a9aaeacbfd578a1b878 kernel-doc-2.6.32-642.15.1.el6.noarch.rpm
177d9718e7126987080c204c791f455c784e298dc76b06a69c333b77d831fb47 kernel-firmware-2.6.32-642.15.1.el6.noarch.rpm
5052e87aacf81ae123a87a0e5002db149a31f27034b857b1654639204ba8dd23 kernel-headers-2.6.32-642.15.1.el6.i686.rpm
772129d87b1914d0529b57da4b7271b2fdb70c389ec9c7cc2ce51c694ded0846 perf-2.6.32-642.15.1.el6.i686.rpm
fd73990afe6d4f3a33de5e1d3ebfb77582017513235a95ae3cc933d72e892da9 python-perf-2.6.32-642.15.1.el6.i686.rpm

x86_64:
644ddd5f661a1ec7674edb21a55fe7187dc418e7ef900fe862df79e2fb6b8af0 kernel-2.6.32-642.15.1.el6.x86_64.rpm
c784e1a7a1339f05c0d0df7fe6bac6fbb0b7a480a1af6ad24116a41b98e38eb6 kernel-abi-whitelists-2.6.32-642.15.1.el6.noarch.rpm
f27b11a0b8e127f44e7e11e6cab0d48c463d68616cb48337a936052e5ac62874 kernel-debug-2.6.32-642.15.1.el6.x86_64.rpm
db434c849f711e6800b56bf3ddc4f77c71a67648e14ec149733bd8b2527d65ca kernel-debug-devel-2.6.32-642.15.1.el6.i686.rpm
c572e0950b1960586d541ce30e2ea0f86b49cbb9f5d51170cd7a5a481ca0617e kernel-debug-devel-2.6.32-642.15.1.el6.x86_64.rpm
a8795311c6c552044450f11a810c285a1c05d6175cb8db313d092ef063ce2673 kernel-devel-2.6.32-642.15.1.el6.x86_64.rpm
118d0af31dc23edff429fbeeadc65e9d13bd5e639a2b0a9aaeacbfd578a1b878 kernel-doc-2.6.32-642.15.1.el6.noarch.rpm
177d9718e7126987080c204c791f455c784e298dc76b06a69c333b77d831fb47 kernel-firmware-2.6.32-642.15.1.el6.noarch.rpm
c54cca97f5e22b0ceaa0c06fe49cb6027dc5a4d8bc5131fb516240a1877608cd kernel-headers-2.6.32-642.15.1.el6.x86_64.rpm
2ee22bfd1cef9df4bc99b20c3c205725d9d38a6fbb4063c9cb96007db753efc1 perf-2.6.32-642.15.1.el6.x86_64.rpm
b8a6e1441a00e961340514f0d5db8faec46c914a041a5eab2d2adf896cc5c79f python-perf-2.6.32-642.15.1.el6.x86_64.rpm

Source:
aab44f74bf793af1559f121a1081a455bce337b0dac04cc504bff37bad40a224 kernel-2.6.32-642.15.1.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

F27 Self Contained Change: Bodhi Non-RPM Artifacts

= Proposed Self Contained Change: Bodhi Non-RPM Artifacts =
https://fedoraproject.org/wiki/Changes/BodhiNonRPMArtifacts

Change owner(s):
* Randy Barlow <bowlofeggs AT fedoraproject DOT org>

Bodhi, the Fedora Updates System, should be able to process more than just RPMs.


== Detailed Description ==
As Fedora starts to deliver more than just RPMs and ISOs, we need a
way to handle delivering updates to these artifacts. Bodhi currently
handles this workflow for RPMs only, but we want to start using it for
other content, such as Docker containers, Flatpak apps, OSTrees, etc.
If it can be tagged in Koji, it should be accepted by Bodhi.


== Scope ==
* Proposal owners:
- Database model changes
- Masher modifications to the push process
- Web UI changes
- CLI modifications
- Unit tests
- Documentation
- Upstream tracker issue: https://github.com/fedora-infra/bodhi/issues/653

* Other developers:
- QA: Taskotron will need handle kicking off tests for non-RPM updates
- QA: Client-side updates-testing tools like fedora-easy-karma could
optionally be updated to detect these new artifacts

* Release engineering:
- We will need to ensure that the current signing process will work
with non-RPM content
- Ensure that the new content has a proper home in the directory structure.
- Releng ticket: #6660
- List of deliverables: N/A (not a System Wide Change)

* Policies and guidelines:
N/A (not a System Wide Change)

* Trademark approval:
N/A (not needed for this Change)
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org

Thursday, February 23, 2017

[USN-3210-1] LibreOffice vulnerability

==========================================================================
Ubuntu Security Notice USN-3210-1
February 23, 2017

LibreOffice vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

LibreOffice could be made to disclose files if it opened a specially crafted
file.

Software Description:
- libreoffice: Office productivity suite

Details:

Ben Hayak discovered that it was possible to make LibreOffice Calc and Writer
disclose arbitrary files to an attacker if a user opened a specially crafted
file with embedded links.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libreoffice                     1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-base                1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-base-core           1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-calc                1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-common              1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-core                1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-math                1:5.1.6~rc2-0ubuntu1~xenial1
  libreoffice-writer              1:5.1.6~rc2-0ubuntu1~xenial1

Ubuntu 14.04 LTS:
  libreoffice                     1:4.2.8-0ubuntu5
  libreoffice-base                1:4.2.8-0ubuntu5
  libreoffice-base-core           1:4.2.8-0ubuntu5
  libreoffice-calc                1:4.2.8-0ubuntu5
  libreoffice-common              1:4.2.8-0ubuntu5
  libreoffice-core                1:4.2.8-0ubuntu5
  libreoffice-math                1:4.2.8-0ubuntu5
  libreoffice-writer              1:4.2.8-0ubuntu5

Ubuntu 12.04 LTS:
  libreoffice                     1:3.5.7-0ubuntu13
  libreoffice-base                1:3.5.7-0ubuntu13
  libreoffice-base-core           1:3.5.7-0ubuntu13
  libreoffice-calc                1:3.5.7-0ubuntu13
  libreoffice-common              1:3.5.7-0ubuntu13
  libreoffice-core                1:3.5.7-0ubuntu13
  libreoffice-math                1:3.5.7-0ubuntu13
  libreoffice-writer              1:3.5.7-0ubuntu13

In general, a standard system update will make all the necessary changes.

References:
  http://www.ubuntu.com/usn/usn-3210-1
  CVE-2017-3157

Package Information:
  https://launchpad.net/ubuntu/+source/libreoffice/1:5.1.6~rc2-0ubuntu1~xenial1
  https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5
  https://launchpad.net/ubuntu/+source/libreoffice/1:3.5.7-0ubuntu13

OpenBSD Foundation 2016 Fundraising

2016 Fund Raising

The OpenBSD Foundation is happy to report that the 2016 fundraising
goal of $250,000 has been more than met with a final donation total
of $573,000!

We wish to thank our contributors large and small. In particular
we would like to extend special thanks to our two Iridium level
($100,000 and above) supporters. The first is Smartisan who made
the largest single donation ever. The second is the OpenBSD community
who together made the second largest donation of 2016.

Other large donors this year were the Core Infrastructure Initiative,
Duck Duck Go, Yandex, 2Keys, Microsoft, Google, Facebook, Hewlett-Packard
Enterprise, Target and genua gmb.

The success of this year's effort will allow the Foundation to
continue to expand its level of support for OpenBSD and related
projects. The Foundation will be able to assume responsibility for
funding more aspects of the project infrastructure including
significant long outstanding machine room repairs and enhancements
such as the high speed fibre connection that was added in 2016.

The Foundation will use its resources to support efforts rebuild
a significant part of the test and release server farm, and to
restock depleted stores and spares for our older architectures.

2017's slate of hackathons is being solidified in the light of the
financial resources now available. These events will continue to
provide a stream of improvements to the OpenBSD projects.

We would like to especially thank the contributors large and small
who have made commitments for continuing donations to the Foundation.
The success of the 2016 fundraising campaign will be much easier
to turn into a regular occurrence thanks to their commitment.

In order to keep OpenBSD and related projects vigorously contributing
to the open software community the Foundation will continue to
strive to improve its financial resources.

Please contribute in 2017!

http://www.openbsdfoundation.org/donations.html

[USN-3211-1] PHP vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJYrxIDAAoJEGVp2FWnRL6T7BkQALSRbePbDSmwVlAVdo3fFACr
icyMuqRUhAba1qF2zGRsOQfKCmKJV7RJPSkd1L58vp21XLSQYz2oSHnb/CjDz4o7
8l6k7bAJAQehAZj6WFd4h5vrYWD8uZ81zMCXrAOlT+okqNBZsyVrAvsKKN9PLj8/
nwBzDEBU4+7Zx8Jd/OrALFsS668zafeXS4EIGkCHEIKMDsBTGBRWKd23lyFQL5GE
8Pyc9pGXnwHQiE9aECUtdkZEVR1JqOWC14PsevDlpvkacY4QkXoYLUu6mNaIISh/
V9/kn4R0H+ZNMXoXd8zkNjFYEQzwXE5IbpjEiSeR5ccqTcKTQRSl82piKEhotcD7
fpP9/Eo39G1NbySCojc3jGhyvff3Fss+JTgkH+empqPkaOWJ3hbcbjvEtgDEKxaL
q4/NfmLKuUXJFjj7fSfku+hqhhVLrFDFUhNm/GturZPKQP40Ls7lObuA8h1+L/CY
IlN/EnzkVLhgIrOwd5vOyXdrRRPnNhY0kcOvZ3JvecprODWyEyUIPCoIKQe95eqz
6leqg8u1N032UPHU9xEfjAmwuoKcSQXsLFh/kUToM1JsvghJRNwE+TwdPXCLsWpX
9UtlzrC4fzuoGON4afQpwJEzEDmwDGfjsNusOL+M5IkavZT1w3zpvQHGI1yBaQZz
9miuLwuDcE2cXW9SKtvJ
=N6Jk
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3211-1
February 23, 2017

php7.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in PHP.

Software Description:
- php7.0: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain invalid objects when
unserializing data. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-7479)

It was discovered that PHP incorrectly handled certain invalid objects when
unserializing data. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9137)

It was discovered that PHP incorrectly handled unserializing certain
wddxPacket XML documents. A remote attacker could use this issue to cause
PHP to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-9935)

It was discovered that PHP incorrectly handled certain invalid objects when
unserializing data. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9936)

It was discovered that PHP incorrectly handled certain EXIF data. A remote
attacker could use this issue to cause PHP to crash, resulting in a denial
of service. (CVE-2016-10158)

It was discovered that PHP incorrectly handled certain PHAR archives. A
remote attacker could use this issue to cause PHP to crash or consume
resources, resulting in a denial of service. (CVE-2016-10159)

It was discovered that PHP incorrectly handled certain PHAR archives. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-10160)

It was discovered that PHP incorrectly handled certain invalid objects when
unserializing data. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2016-10161)

It was discovered that PHP incorrectly handled unserializing certain
wddxPacket XML documents. A remote attacker could use this issue to cause
PHP to crash, resulting in a denial of service. (CVE-2016-10162)

It was discovered that PHP incorrectly handled certain invalid objects when
unserializing data. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2017-5340)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
libapache2-mod-php7.0 7.0.15-0ubuntu0.16.10.2
php7.0-cgi 7.0.15-0ubuntu0.16.10.2
php7.0-cli 7.0.15-0ubuntu0.16.10.2
php7.0-fpm 7.0.15-0ubuntu0.16.10.2

Ubuntu 16.04 LTS:
libapache2-mod-php7.0 7.0.15-0ubuntu0.16.04.2
php7.0-cgi 7.0.15-0ubuntu0.16.04.2
php7.0-cli 7.0.15-0ubuntu0.16.04.2
php7.0-fpm 7.0.15-0ubuntu0.16.04.2

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
http://www.ubuntu.com/usn/usn-3211-1
CVE-2016-10158, CVE-2016-10159, CVE-2016-10160, CVE-2016-10161,
CVE-2016-10162, CVE-2016-7479, CVE-2016-9137, CVE-2016-9935,
CVE-2016-9936, CVE-2017-5340

Package Information:
https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.10.2
https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2

[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-17:04.mandoc

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-17:04.mandoc Errata Notice
The FreeBSD Project

Topic: makewhatis output is not reproducible

Category: contrib
Module: mandoc
Announced: 2017-02-23
Credits: Ingo Schwarze, Ed Maste
Affects: FreeBSD 11.0-RELEASE
Corrected: 2016-11-26 03:39:02 UTC (stable/11, 11.0-STABLE)
2017-02-23 07:11:48 UTC (releng/11.0, 11.0-RELEASE-p8)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

I. Background

The makewhatis utility extracts keywords from UNIX manuals and indexes
them in a database for fast retrieval by apropos(1), whatis(1), and
man(1)'s -k option.

II. Problem Description

The generation of makewhatis database is not reproducible.

III. Impact

The freebsd-update(8) build procedure may consider mandoc.db as changed when
built multiple times.

IV. Workaround

No workaround is available, but the impact is mostly cosmetic.

V. Solution

Perform one of the following:

1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.

Reboot is not necessary.

2) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

Reboot is not necessary.

3) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/EN-17:04/mandoc.patch
# fetch https://security.FreeBSD.org/patches/EN-17:04/mandoc.patch.asc
# gpg --verify mandoc.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/11/ r309183
releng/11.0/ r314125
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=214545>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-17:04.mandoc.asc>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.18 (FreeBSD)

iQIzBAEBCgAdFiEEHPf/b631yp++G4yy7Wfs1l3PaucFAliujOMACgkQ7Wfs1l3P
aucxsA//fsEp6miJAsXLBOFxI1hiRheHb6HlOaXYrMo59sKLgRGRipe34AxIq3Ca
cYvVRHOEpXlUZNMvModg/P42SkkQLDi+2tIenvQUG5T5r3xSRTAHOU0pSRlpfjaA
8OCIaZaWYDIcTOEfaQocIbjwuKfzw5qVxZY6Ot3NPz0QEpOSzFGkbRrM8JxkrVyg
ROtzY/rqaDbhfdKyTCS8PZCIW4ZwNiBjAV9kZysviN3RUSQvLaxEC+vTDjU9BBm5
CKIU3y0aoSlO4W6A9ahqVb/4hX7A2WBoFpfhMVXsVOzi4SkJhaFKNdjwbq6Nrmxr
hePKGTSYVtcVIaiyf0rJwHDvGK6y4NKCTTqCwlQ7hrMGZHY2D5t5NAdd10uvIrv6
PDQkJBap5hZTnSeJ+rZt1jSUR1qAJ+xb86Fe1dG30fs6AsKpbYJEpTLWgSXmOfp/
GQT0SCxv5mxtxMzIom8MUQipYay1cUIiXAh/wlfxERNWHHt3UXoP4/wS9Df+26w9
zQ/5fk3TbtxAcCpZWBeZr1+pKIomQ4+51wU7zgyjAHvGRDesoA54XS3BOTJPWKnY
G1iNBWECSQC26jwzmSv/MMXf4BqT6ezZXXZ22uMeYQCTD4p0tiC6/H4RUEVSgOSl
TnZ026b3FQRlE6FIOYPK9a4AipnLYu4NW6f9tsJquwRyElLSd/U=
=oyNi
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-17:03.hyperv

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-17:03.hyperv Errata Notice
The FreeBSD Project

Topic: Compatibility with Hyper-V/storage after KB3172614 or
KB3179574

Category: core
Module: hyperv/storvsc
Announced: 2017-02-23
Credits: Microsoft OSTC
Affects: FreeBSD 11.0-RELEASE
Corrected: 2016-10-19 07:43:39 UTC (stable/11, 11.0-STABLE)
2017-02-23 07:11:48 UTC (releng/11.0, 11.0-RELEASE-p8)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

I. Background

Hyper-V is a default hypervisor provided on Windows server by Microsoft.
ATA driver is the legacy storage driver for FreeBSD on Hyper-V, now they
are replaced by synthetic driver which has better performance. There are
issues when attaching synthetic storage driver for FreeBSD 11 on some of
Hyper-V hosts.

II. Problem Description

There are some compatibility issues with the FreeBSD Hyper-V driver,
which will cause the OS disk to be detached if August 2016 update rollup
is applied on Windows host (KB3172614 or KB3179574).

III. Impact

FreeBSD 11.0 can not be installed on a guest system on Hyper-V host.

IV. Workaround

On Hyper-V connection, when the installer boot prompt, select

3. Escape to the loader prompt

Then:

set hw.ata.disk_enable=1
boot.

Note: this workaround force FreeBSD to use legacy storage driver
which is much slower than synthetic driver.

V. Solution

Perform one of the following:

1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.

Afterward, reboot the system.

2) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

Afterward, reboot the system.

3) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/EN-17:03/hyperv.patch
# fetch https://security.FreeBSD.org/patches/EN-17:03/hyperv.patch.asc
# gpg --verify hyperv.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/11/ r307617
releng/11.0/ r314125
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=212721>

<URL:https://support.microsoft.com/en-au/help/24717/windows-8-1-and-windows-server-2012-r2-update-history>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.18 (FreeBSD)

iQIzBAEBCgAdFiEEHPf/b631yp++G4yy7Wfs1l3PaucFAliujNwACgkQ7Wfs1l3P
auea7BAAtYKNH1OVGWZ2frFoaVAuzLA0Gow599XCM5ycF39HTlavmoR1+KN9g8Gh
r2wEBvIM/Yzla16mmLEzt7QLeSFMP1mgVb1lUtvAp62b/lzb2ImIvL3qhury0nop
eczup/A/nFOOgOa/IEMsxqi5noB5e2ODkWEOayiLNd5fmD/BF+yACEKi0YI0krQY
Oonq4N9ah7z4rT8OYC2LNQPvc00ZAAq9eq/IDdtWDvLgpxOF1W+dJ0MAzLhQwNJn
9cdW13AcrdJHxzyjAGeOd1pedWFs0ueEXLI+J5pVOvpZd3WeAc9Fls8t7GNgYwvf
dpf9uaB765n5tZCa+gc8h2eSzY59aEAQOtHXTqlMGp3ACl7D7Gjmhh42Vp4fgySb
zeeKEqAnNay4NdBEGt/U9CjycNKMKi6/bqLpEq3rxu8QFPzeXuwIB3favj8MpIUI
ZMda4CQ1E9XLgG6YoupSpnVSbvNFZIEQ2RHzZesKlIoQIM4OPSBWPGjSR9UDMNKH
mxb/cWMwO9N4G7xzKSULuIAF33wZYkaKqTfzOKVtOEZ7hlBPlqzfXK2MNqlbc0PO
3bqPvrg8KXL8OyswEy0sZaptQs/jTUZjqI9/JNWY+IdRR1clVrRdpg/YWljwqqvb
hFIarahbNC1fvsMTeAFq8QBGXkoy6ovmjpKrhBfPNpaiL5ccuWU=
=nMwL
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-17:02.yp

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-17:02.yp Errata Notice
The FreeBSD Project

Topic: NIS master updates are not pushed to NIS slave

Category: core
Module: yppush, ypxfr
Announced: 2017-02-23
Credits: Mark Johnston
Affects: FreeBSD 11.0-RELEASE
Corrected: 2016-10-19 17:18:48 UTC (stable/11, 11.0-STABLE)
2017-02-23 07:11:48 UTC (releng/11.0, 11.0-RELEASE-p8)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

I. Background

yppush(8) and ypxfr(8) utilities are used to synchronize databases from
a master NIS server.

II. Problem Description

A bug present in FreeBSD 11.0 prevents these utilities from working
properly. In particular, an attempt to synchronize a non-empty map
causes yppush(8) to crash.

III. Impact

The problem prevents updates to a master NIS server from being propagated
to NIS slave servers.

IV. Workaround

No workaround is available, but NIS configurations which do not make
use of NIS slave servers are unaffected.

V. Solution

Perform one of the following:

1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.

2) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

A reboot is not required. However, the system administrator may need to
manually run yppush(8) after the update have been applied on slave systems.

3) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/EN-17:02/yp.patch
# fetch https://security.FreeBSD.org/patches/EN-17:02/yp.patch.asc
# gpg --verify yp.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.

A reboot is not required. However, the system administrator may need to
manually run yppush(8) after the update have been applied on slave systems.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/11/ r307642
releng/11.0/ r314125
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=213506>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-17:02.yp.asc>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.18 (FreeBSD)

iQIzBAEBCgAdFiEEHPf/b631yp++G4yy7Wfs1l3PaucFAliujNcACgkQ7Wfs1l3P
aucX/Q/5AbGPtToi+NC4OB0sNJbCiJD5WOP7tmbNipDm5SGoItN+lXQSv+FN1wbF
9R4vhqBqDROE35PF9QUWdFb1qE4i37lD4DznK7r1urg3n7CWx5zcPYAz3PNA7FFX
IJixTM4fjhoWoKAWMLZhc+7+ez7HB83AZrExXDBFRnj7SvceJw6B//yCRB/he9l3
trE5yvUyAiSPylG5qfA6upsJftXsluajq0uQ/yD4iGfqT8nqjOrsd4z64S6+3wTT
lnZHyjNEfIqVQ81Lp9EIsqaU7pyvPrjRQqxsHI+rZO/2YVA/RDokeIcq6s+8GN76
/H7U8XoEuLFNq39s+fHOLTIPGjSM5PN1jqreoJTXnLFqpDtc2WI3W6cvMUY3lD2y
rW3jDrQOxKF8E9qD/wyi7Sa74cC4PduEe9F+fwNOf+gQUtd/NF+OcnSo0imUnmvU
VJy7FHSUQWZY7ZDW0L7CUT6IDBvIncUKlt1DX4b8M9GkX65FtXmd4risExxBlGDh
ikMD+qzCE8tlqzXKPzEmZNLgsAj0nJiZIcD6kMDORLNyzdI7AeqSazg6Pt70XstR
r+GjK1Hclp/lTqaEJLuBrkd2LJGI2Wcyp/nRZ6OifyduvRwk5vKPhQf792zqx+FK
0sZ1T7po0aop1sDFRDZKCHMRxxpKfd5BTxEyQ24v7GL02Dz/rVk=
=zlKa
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-17:01.pcie

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-17:01.pcie Errata Notice
The FreeBSD Project

Topic: System hang when booting when PCI-express HotPlug is enabled

Category: core
Module: kernel
Announced: 2017-02-23
Credits: Alan Somers, Dave Baukus
Affects: FreeBSD 11.0
Corrected: 2017-02-07 22:40:38 UTC (stable/11, 11.0-STABLE)
2017-02-23 07:11:48 UTC (releng/11.0, 11.0-RELEASE-p8)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

I. Background

Native PCI-express HotPlug permits PCI-express devices to be added and
removed at runtime in slots that support HotPlug.

II. Problem Description

Some PCI-express slots indicate partial support for PCI-express HotPlug
in the capability registers associated with an individual slot. The
PCI-express HotPlug driver attempted to configure these slots for HotPlug
operation. However, since these slots do not fully support HotPlug,
enabling HotPlug results in unpredictable behavior.

III. Impact

On at least some systems, booting a kernel with PCI-express HotPlug
support can hang.

IV. Workaround

The hw.pci.enable_pcie_hp loader tunable can be set to 0 to disable
support for PCI-express HotPlug before booting an affected kernel.

V. Solution

Perform one of the following:

1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.

Afterward, reboot the system.

2) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

Afterward, reboot the system.

3) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/EN-17:01/pcie.patch
# fetch https://security.FreeBSD.org/patches/EN-17:01/pcie.patch.asc
# gpg --verify pcie.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/11/ r313408
releng/11.0/ r314125
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=211699>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-17:01.pcie.asc>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.18 (FreeBSD)

iQIzBAEBCgAdFiEEHPf/b631yp++G4yy7Wfs1l3PaucFAliujNEACgkQ7Wfs1l3P
aucj/RAAsB/+cWKAaf5pLiP9Hh9Rjmry8ZMyiG6RVBB22N8UM34ioiPPSjTu1ogQ
ZCP31fUqCWDwwQgVu6/Nl4Ur/NjeOYMjHAzxyjlgrFPx2RliptZCakMSA7NDBm7h
vhFxlvBdLvYOL1sDTPwO1HuaIRl8f6BMa3p99Ubaur2Blw7Zn2gDaIEDdiG8K2LN
m+R+yJvDqJmpQJcTiqkxMrcfemcmpuVkH/PTaQhjcuZfslQW8eL82dfXsmkuv5tz
J1cXJHSZHhX1Bq+cuKpAVp7rV65iud5nElt1NJiG4GC61h289nSoqsUebWcjzx4j
0XVwCxitLVqgybdD+OtJejxBwgwWnB3K2xicu5WYOSo/jUhXGRLXZTSk1COvDwZZ
4ndeGv1RwwknQTNxfHlnOH9uZozvQq1fCyXZ2CBnsfKs5gxW2GAF1+xTGXD2tSAJ
ntyc9JhiV0EmixG/aiDk8D6HaUnvcqvtUHCewbNXKy2xqRbnNDal613vzhgbNWKi
RqFoPDDCaLsD9uoL/DSh8R8sHh8QuNq903JxPODM0MoioWYGj+xzz5RNY1EwlhcO
nRI3CwmQr/Oxow+ajEqT4MRaQtmHSudmvcF6Syyw6Rt0lWF4R6KxYk2fPdaW18N0
LU9fqH2IWGSmzPMdnJKI6I49jtOiUaIfXCAGpX15jpVN/1ZUg1k=
=x/qY
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

[FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-17:02.openssl

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-SA-17:02.openssl Security Advisory
The FreeBSD Project

Topic: OpenSSL multiple vulnerabilities

Category: contrib
Module: openssl
Announced: 2017-02-23
Affects: All supported versions of FreeBSD.
Corrected: 2017-01-26 19:14:14 UTC (stable/11, 11.0-STABLE)
2017-02-23 07:11:48 UTC (releng/11.0, 11.0-RELEASE-p8)
2017-01-27 07:45:06 UTC (stable/10, 10.3-STABLE)
2017-02-23 07:12:18 UTC (releng/10.3, 10.3-RELEASE-p16)
CVE Name: CVE-2016-7055, CVE-2017-3731, CVE-2017-3732

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I. Background

FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is
a collaborative effort to develop a robust, commercial-grade, full-featured
Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library.

II. Problem Description

If an SSL/TLS server or client is running on a 32-bit host, and a specific
cipher is being used, then a truncated packet can cause that server or
client to perform an out-of-bounds read, usually resulting in a crash.
[CVE-2017-3731]

There is a carry propagating bug in the x86_64 Montgomery squaring procedure.
No EC algorithms are affected. Analysis suggests that attacks against RSA and
DSA as a result of this defect would be very difficult to perform and are not
believed likely. Attacks against DH are considered just feasible (although
very difficult) because most of the work necessary to deduce information
about a private key may be performed offline. The amount of resources
required for such an attack would be very significant and likely only
accessible to a limited number of attackers. An attacker would additionally
need online access to an unpatched system using the target private key in
a scenario with persistent DH parameters and a private key that is shared
between multiple clients. [CVE-2017-3732]

Montgomery multiplication may produce incorrect results. [CVE-2016-7055]

III. Impact

A remote attacker may trigger a crash on servers or clients that supported
RC4-MD5. [CVE-2017-3731]

A remote attacker may be able to deduce information about a private key,
but that would require enormous amount of resources. [CVE-2017-3732,
CVE-2016-7055]

IV. Workaround

No workaround is available.

V. Solution

Perform one of the following:

1) Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date.

Restart all daemons that use the library, or reboot the system.

2) To update your vulnerable system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

Restart all daemons that use the library, or reboot the system.

3) To update your vulnerable system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

[FreeBSD 11.0]
# fetch https://security.FreeBSD.org/patches/SA-17:02/openssl-11.patch
# fetch https://security.FreeBSD.org/patches/SA-17:02/openssl-11.patch.asc
# gpg --verify openssl-11.patch.asc

[FreeBSD 10.3]
# fetch https://security.FreeBSD.org/patches/SA-17:02/openssl-10.patch
# fetch https://security.FreeBSD.org/patches/SA-17:02/openssl-10.patch.asc
# gpg --verify openssl-10.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.

Restart all daemons that use the library, or reboot the system.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r312863
releng/10.3/ r314125
stable/11/ r312826
releng/11.0/ r314126
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7055>

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3731>

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3732>

<URL:https://www.openssl.org/news/secadv/20170126.txt>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-17:02.openssl.asc>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.18 (FreeBSD)

iQIzBAEBCgAdFiEEHPf/b631yp++G4yy7Wfs1l3PaucFAliujOsACgkQ7Wfs1l3P
aufZHhAAy8U5oOrLGq0XH8Dumpkyc+bFOmsEh+S1hL6jFL13jUVpDqogZ3w/a7If
Hcqiyipx5dbcGbHJayokfimkxPcIYydYQK9NwWaXVlnZifvgWka+KxtcD0u2A8S5
cpTbNl+CALQQqEF3+JmOc4Uq2Dtui0xFG1N5Og4oF5Uo+lvQh4bcJ1UbfhMdq8EG
US3hGlJLJJW75m3jkgHyu0o7A0swnNTUQrW9Z0p/3iTiel7fM57d/N1who+kt59V
UErXTzMDBT1kkWRne0aTA71gdy3SUeRiVi9/LWggjIRJNyMnQjO3UI2UOIHLLQAG
CXcZLPekB87iHZxMAw8oV6b4GIkJhqUFW2ep2AZkUdDZ2Mup9bDrx/0Ik0jHjyQY
KEmZDroHvP8z569q+aWfIIpMXPv6zJTnent45U2/q13wMHJwWsADu9ukeWKTw7wI
P0Rc3vht+AXbXFi9SjxwdldgrVszV7x8Yi6W9KhHsGqCl6NBCW9Md/PWbNQQUVkq
I5tV0WB3pTwOk0yMi3h/okM9VBr1lPDU18W0he5T9wbOh4w0jwFb8AqMu1slst3l
9MlhRfO/4LIDlfRQ/dj4dOfVLZqEd/xleax99yFXZUzibUYrOMlBxNaKvV80plwB
Kg2Hr3DJuJa3599kNgXMCNV1lRIOJbJ9dRmX6B0YzMgvxKPIXY4=
=8Jsr
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

Wednesday, February 22, 2017

[CentOS-announce] CESA-2017:0294 Important CentOS 7 kernel Security Update

CentOS Errata and Security Advisory 2017:0294 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2017-0294.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
399d85490609511d4f57270f4db2ae22aff1e77dbfb9fa1735f3acd74a32b15d kernel-3.10.0-514.6.2.el7.x86_64.rpm
ade938b455c925303441ff53433c55c4507501c34537a8dac3267f2027ac70a9 kernel-abi-whitelists-3.10.0-514.6.2.el7.noarch.rpm
b9cbfd11d08961b8c9c78e82e669693b33063f7e5c5cd4835f17403e7a8adfd4 kernel-debug-3.10.0-514.6.2.el7.x86_64.rpm
f845b17f3955c7e37c80ae44810c623e5e8679159395eb71374e3f081dbf8695 kernel-debug-devel-3.10.0-514.6.2.el7.x86_64.rpm
b7fe4fc10de18db85e12d32dcb702229ed2fb3137e7cee784f5a15a2459f5db2 kernel-devel-3.10.0-514.6.2.el7.x86_64.rpm
d2043d02d55f4189e3462149fbe80f8e281170d07acd5f4153636fdec89ab3c5 kernel-doc-3.10.0-514.6.2.el7.noarch.rpm
5849bd28663d4c8a112121b13c19b10b2f43decfc3a1bc3b4246227a3e255297 kernel-headers-3.10.0-514.6.2.el7.x86_64.rpm
640ba1792316b03339098f76f3bab13d2ca79a1f309122df21c3bf85ccba90e4 kernel-tools-3.10.0-514.6.2.el7.x86_64.rpm
8e9dd3262234c4d1cd6bb1cfe591111189bba8282e56cf284c5086c5977c7f96 kernel-tools-libs-3.10.0-514.6.2.el7.x86_64.rpm
35d8fee07d663665c297c3d6bd4dc623afc6fcae7bde1f09be88d4773a2837f9 kernel-tools-libs-devel-3.10.0-514.6.2.el7.x86_64.rpm
c416658118df7791b9b8eb4fe9fbf941e1cb2005fd91b7f80b29232bf3b1aa7b perf-3.10.0-514.6.2.el7.x86_64.rpm
14c06f8de0921bd9a671feff1813b6af0c58a75fbe5f47ef92e4e6324c6c7249 python-perf-3.10.0-514.6.2.el7.x86_64.rpm

Source:
19b33fba0c0c2c8eb838fcb65983c7dadc1c67b42c9b72e7dcd271d2c7b73572 kernel-3.10.0-514.6.2.el7.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce