<?xml version="1.0"?>
<!DOCTYPE webpage
  PUBLIC "-//NetBSD//DTD Website-based NetBSD Extension//EN"
	 "http://www.NetBSD.org/XML/htdocs/lang/share/xml/website-netbsd.dtd">

<webpage id="support-security-patches-1.6">
<config param="desc" value="NetBSD 1.6 Security Advisories"/>
<config param="cvstag" value="$NetBSD: patches-1.6.xml,v 1.4 2007/07/29 04:41:38 kano Exp $"/>
<config param="rcsdate" value="$Date: 2007/07/29 04:41:38 $"/>
<head>
<title>NetBSD 1.6 Security Advisories</title>
</head>

<sect1 id="patches-1.6">

<para>
Below is the list of advisories applicable to the
<ulink url="../../releases/formal-1.6/">NetBSD 1.6</ulink>
release:
</para>

<itemizedlist>
<listitem>A description and resolution procedure for
    sysctl(3) local denial of service        
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-013</ulink></listitem>
<listitem>A description and resolution procedure for
    SIOCGIFALIAS ioctl may cause system crash          
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-012.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-012</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail race condition       
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc">                       
    NetBSD Security Advisory NetBSD-SA2006-010</ulink></listitem>
<listitem>A description and resolution procedure for
    False detection of Intel hardware RNG           
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-009</ulink></listitem>
<listitem>A description and resolution procedure for
    mail(1) creates record file with insecure umask        
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-007.txt.asc">                       
    NetBSD Security Advisory NetBSD-SA2006-007</ulink></listitem>
<listitem>A description and resolution procedure for
    bridge memory disclosure        
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc">                       
    NetBSD Security Advisory NetBSD-SA2006-005</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple denial of services issues with racoon         
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-003.txt.asc">                       
    NetBSD Security Advisory NetBSD-SA2006-003</ulink></listitem>
<listitem>A description and resolution procedure for
    settimeofday() time wrap
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Kernfs kernel memory disclosure
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-001</ulink></listitem>
<listitem>A description and resolution procedure for
    ptrace() permissions after S[UG]ID and exec()
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-013</ulink></listitem>
<listitem>A description and resolution procedure for
    ntpd may start with different group id than desired
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-011.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-011</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL <quote>man in the middle</quote> can force weak protocol
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-010</ulink></listitem>
<listitem>A description and resolution procedure for
    insecure /tmp file usage when building using imake
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-009</ulink></listitem>
<listitem>A description and resolution procedure for
    heap memory corruption in FreeBSD compat code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-008</ulink></listitem>
<listitem>A description and resolution procedure for
    multiple vulnerabilities in CVS
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-006.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-006</ulink></listitem>
<listitem>A description and resolution procedure for
    a buffer overflows in MIT Kerberos 5 telnet client
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-004</ulink></listitem>
<listitem>A description and resolution procedure for
    Local DoS via audio device with specific drivers
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Insufficient argument validation in compat code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-010</ulink></listitem>
<listitem>A description and resolution procedure for
    a ftpd root escalation
    can be found in
    <ulink
url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-009.txt.asc">     
    NetBSD Security Advisory NetBSD-SA2004-009</ulink></listitem>
<listitem>A description and resolution procedure for
    CVS server vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-008</ulink></listitem>
<listitem>A description and resolution procedure for
    TCP protocol and implementation vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc">     
    NetBSD Security Advisory NetBSD-SA2004-006</ulink></listitem>
<listitem>A description and resolution procedure for
    Denial of service vulnerabilities in OpenSSL
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc">     
    NetBSD Security Advisory NetBSD-SA2004-005</ulink></listitem>
<listitem>A description and resolution procedure for
    shmat reference counting bug
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-004</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL 0.9.6 ASN.1 parser vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-003</ulink></listitem>
<listitem>A description and resolution procedure for
    Inconsistent IPv6 path MTU discovery handling
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Insufficient packet validation in racoon IKE daemon
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2004-001</ulink></listitem>
<listitem>A description and resolution procedure for
    DNS negative cache poisoning
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-018.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-018</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL multiple vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-017.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-017</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail - another prescan() bug CAN-2003-0694
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-016.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-016</ulink></listitem>
<listitem>A description and resolution procedure for
    Remote and local vulnerabilities in XFree86 font libraries
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-015.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-015</ulink></listitem>
<listitem>A description and resolution procedure for
    Insufficient argument checking in sysctl(2)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-014.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-014</ulink></listitem>
<listitem>A description and resolution procedure for
    Out of bounds memset(0) in sshd
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-012.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-012</ulink></listitem>
<listitem>A description and resolution procedure for
    off-by-one error in realpath(3)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-011.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-011</ulink></listitem>
<listitem>A description and resolution procedure for
    remote panic in OSI networking code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2003-010</ulink></listitem>
<listitem>A description and resolution procedure for
    sendmail buffer overrun in prescan() address parser       
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-009.txt.asc">NetBSD
    Security Advisory SA2003-009</ulink></listitem>
<listitem>A description and resolution procedure for
	faulty length checks in xdrmem_getbytes
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc">NetBSD
    Security Advisory SA2003-008</ulink></listitem>
<listitem>A description and resolution procedure for
	(Another) Encryption weakness in OpenSSL code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc">NetBSD
    Security Advisory SA2003-007</ulink></listitem>
<listitem>A description and resolution procedure for
    Cryptographic weaknesses in Kerberos v4 protocol       
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-006.txt.asc">NetBSD
    Security Advisory SA2003-006</ulink></listitem>
<listitem>A description and resolution procedure for
	RSA timing attack in OpenSSL code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-005.txt.asc">NetBSD
    Security Advisory SA2003-005</ulink></listitem>
<listitem>A description and resolution procedure for
	Format string vulnerability in zlib gzprintf()
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc">NetBSD
    Security Advisory SA2003-004</ulink></listitem>
<listitem>A description and resolution procedure for
        Buffer Overflow in file(1)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc">NetBSD
    Security Advisory SA2003-003</ulink></listitem>
<listitem>A description and resolution procedure for
        Malformed header Sendmail vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-002.txt.asc">NetBSD
    Security Advisory SA2003-002</ulink></listitem>
<listitem>A description and resolution procedure for
        Encryption weakness in OpenSSL code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc">NetBSD
    Security Advisory SA2003-001</ulink></listitem>
<listitem>A description and resolution procedure for
        named(8) multiple denial of service and remote execution of code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-029.txt.asc">NetBSD
    Security Advisory SA2002-029</ulink></listitem>
<listitem>A description and resolution procedure for
        Buffer overrun in getnetbyname/getnetbyaddr
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-028.txt.asc">NetBSD
    Security Advisory SA2002-028</ulink></listitem>
<listitem>A description and resolution procedure for
        ftpd STAT output non-conformance can deceive firewall devices
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-027.txt.asc">NetBSD
    Security Advisory SA2002-027</ulink></listitem>
<listitem>A description and resolution procedure for
        buffer overrun in kadmind
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-026.txt.asc">NetBSD
    Security Advisory SA2002-026</ulink></listitem>
<listitem>A description and resolution procedure for
        trek(6) buffer overrun
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-025.txt.asc">NetBSD
    Security Advisory SA2002-025</ulink></listitem>
<listitem>A description and resolution procedure for
        IPFilter FTP proxy vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-024.txt.asc">NetBSD
    Security Advisory SA2002-024</ulink></listitem>
<listitem>A description and resolution procedure for
        sendmail smrsh vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-023.txt.asc">NetBSD
    Security Advisory SA2002-023</ulink></listitem>
<listitem>A description and resolution procedure for
        buffer overrun in pic(1)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-022.txt.asc">NetBSD
    Security Advisory SA2002-022</ulink></listitem>
<listitem>A description, <ulink
url="ftp://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2002-021-rogue.patch">patch</ulink>,
and resolution procedure for
        rogue vulnerability
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-021.txt.asc">NetBSD
    Security Advisory SA2002-021</ulink></listitem>
<listitem>A description and resolution procedure for
        Buffer overrun in talkd
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-019.txt.asc">NetBSD
    Security Advisory SA2002-019</ulink></listitem>
<listitem>A description and resolution procedure for
        Multiple security isses with kfd daemon
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2002-018.txt.asc">NetBSD
    Security Advisory SA2002-018</ulink></listitem>
</itemizedlist>
</sect1>
</webpage>

