<?xml version="1.0"?>
<!DOCTYPE webpage
  PUBLIC "-//NetBSD//DTD Website-based NetBSD Extension//EN"
	 "http://www.NetBSD.org/XML/htdocs/lang/share/xml/website-netbsd.dtd">

<webpage id="support-security-patches-1.6.2">
<config param="desc" value="NetBSD 1.6.2 Security Advisories"/>
<config param="cvstag" value="$NetBSD: patches-1.6.2.xml,v 1.4 2007/07/29 04:41:38 kano Exp $"/>
<config param="rcsdate" value="$Date: 2007/07/29 04:41:38 $"/>
<head>
<title>NetBSD 1.6.2 Security Advisories</title>
</head>

<sect1 id="patches-1.6.2">
<para>
Below is the list of advisories applicable to the
<ulink url="../../releases/formal-1.6/">NetBSD 1.6.2</ulink>
release:
</para>

<itemizedlist>
<listitem>A description and resolution procedure for
    sysctl(3) local denial of service        
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-013</ulink></listitem>
<listitem>A description and resolution procedure for
    SIOCGIFALIAS ioctl may cause system crash          
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-012.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-012</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail race condition
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-010</ulink></listitem>
<listitem>A description and resolution procedure for
    False detection of Intel hardware RNG           
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-009</ulink></listitem>
<listitem>A description and resolution procedure for
    mail(1) creates record file with insecure umask
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-007.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-007</ulink></listitem>
<listitem>A description and resolution procedure for
    bridge memory disclosure
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-005</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple denial of services issues with racoon
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-003.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-003</ulink></listitem>
<listitem>A description and resolution procedure for
    settimeofday() time wrap
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Kernfs kernel memory disclosure
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-001</ulink></listitem>
<listitem>A description and resolution procedure for
    ntpd may start with different group id than desired
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-011.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-011</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL <quote>man in the middle</quote> can force weak protocol
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-010</ulink></listitem>
<listitem>A description and resolution procedure for
    insecure /tmp file usage when building using imake
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-009</ulink></listitem>
<listitem>A description and resolution procedure for
    heap memory corruption in FreeBSD compat code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-008</ulink></listitem>
<listitem>A description and resolution procedure for
    multiple vulnerabilities in CVS
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-006.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-006</ulink></listitem>
<listitem>A description and resolution procedure for
    a buffer overflows in MIT Kerberos 5 telnet client
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-004</ulink></listitem>
<listitem>A description and resolution procedure for
    Local DoS via audio device with specific drivers
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Insufficient argument validation in compat code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-010</ulink></listitem>
<listitem>A description and resolution procedure for
    a ftpd root escalation
    can be found in
    <ulink
url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-009.txt.asc">     
    NetBSD Security Advisory NetBSD-SA2004-009</ulink></listitem>
<listitem>A description and resolution procedure for
    CVS server vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-008</ulink></listitem>
<listitem>A description and resolution procedure for
    TCP protocol and implementation vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc">     
    NetBSD Security Advisory NetBSD-SA2004-006</ulink></listitem>
<listitem>A description and resolution procedure for
    Denial of service vulnerabilities in OpenSSL
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc">     
    NetBSD Security Advisory NetBSD-SA2004-005</ulink></listitem>
</itemizedlist>
</sect1>
</webpage>

