<?xml version="1.0"?>
<!DOCTYPE webpage
  PUBLIC "-//NetBSD//DTD Website-based NetBSD Extension//EN"
	 "http://www.NetBSD.org/XML/htdocs/lang/share/xml/website-netbsd.dtd">

<webpage id="support-security-patches-2.0.3">
<config param="desc" value="NetBSD 2.0.3 Security Advisories"/>
<config param="cvstag" value="$NetBSD: patches-2.0.3.xml,v 1.6 2008/02/28 20:40:28 adrianp Exp $"/>
<config param="rcsdate" value="$Date: 2008/02/28 20:40:28 $"/>
<head>
<title>NetBSD 2.0.3 Security Advisories</title>
</head>

<sect1 id="patches-2.0.3">

<para>
Below is the list of advisories applicable to the
<ulink url="../../releases/formal-2.0/">NetBSD 2.0.3</ulink>
release:
</para>

<itemizedlist>
<listitem>A description and resolution procedure for
    IPsec in IPv6 Denial of Service
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-003.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-003</ulink></listitem>
<listitem>A description and resolution procedure for
    Endianness issue in fast_ipsec(4)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-002</ulink></listitem>
<listitem>A description and resolution procedure for
    file(1) Integer overflow
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-001</ulink></listitem>
<listitem>A description and resolution procedure for
    BIND cryptographically weak query IDs
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-007.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-007</ulink></listitem>
<listitem>A description and resolution procedure for
    IPv6 Type 0 Routing Header
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-005.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-005</ulink></listitem>
<listitem>A description and resolution procedure for
    Insufficient length checking in iso(4)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-004</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflows in Render and DBE extensions
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflow in ktruser()
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-001</ulink></listitem>
<listitem>A description and resolution procedure for
    libc glob(3) buffer overflow
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-027.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-027</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple denial of service issues
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-026.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-026</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple information/memory leakage issues
    can be found in     
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-025.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-025</ulink></listitem>
<listitem>A description and resolution procedure for
    systrace(4) integer overflow    
    can be found in                     
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-024.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-024</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL RSA Signature Forgery
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-023.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-023</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflows in CID-keyed font parser
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-021.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-021</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflows in PCF font parsers
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-020.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-020</ulink></listitem>
<listitem>A description and resolution procedure for
    Malicious PPP options can overrun a kernel buffer
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-019.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-019</ulink></listitem>
<listitem>A description and resolution procedure for
    sail(6), dm(8) and tetris(6) buffer overflows
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-018.txt.asc">                       
    NetBSD Security Advisory NetBSD-SA2006-018</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail malformed multipart MIME messages
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-017.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-017</ulink></listitem>
<listitem>A description and resolution procedure for                    
    IPv6 socket options can crash the system             
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-016.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-016</ulink></listitem>
<listitem>A description and resolution procedure for                    
    FPU Information leak on i386/amd64/Xen platforms with AMD CPUs             
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-015.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-015</ulink></listitem>
<listitem>A description and resolution procedure for
    sysctl(3) local denial of service
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-013</ulink></listitem>
<listitem>A description and resolution procedure for
    SIOCGIFALIAS ioctl may cause system crash
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-012.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-012</ulink></listitem>
<listitem>A description and resolution procedure for
    IPSec replay attack
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-011.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-011</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail race condition
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-010</ulink></listitem>
<listitem>A description and resolution procedure for
    False detection of Intel hardware RNG           
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-009</ulink></listitem>
<listitem>A description and resolution procedure for
    Malformed ELF interpreter causes system crash
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-008</ulink></listitem>
<listitem>A description and resolution procedure for
    mail(1) creates record file with insecure umask
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-007.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-007</ulink></listitem>
<listitem>A description and resolution procedure for
    bridge memory disclosure
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-005</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple denial of services issues with racoon  
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-003.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-003</ulink></listitem>
<listitem>A description and resolution procedure for
    settimeofday() time wrap
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Kernfs kernel memory disclosure
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-001</ulink></listitem>
<listitem>A description and resolution procedure for
    ptrace() permissions after S[UG]ID and exec()
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-013</ulink></listitem>
<listitem>A description and resolution procedure for
    SO_LINGER argument checking DIAGNOSTIC panic
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-012.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-012</ulink></listitem>
<listitem>A description and resolution procedure for
    ntpd may start with different group id than desired
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2005-011.txt.asc">
    NetBSD Security Advisory NetBSD-SA2005-011</ulink></listitem>
</itemizedlist>
</sect1>
</webpage>

