<?xml version="1.0"?>
<!DOCTYPE webpage
  PUBLIC "-//NetBSD//DTD Website-based NetBSD Extension//EN"
	 "http://www.NetBSD.org/XML/htdocs/lang/share/xml/website-netbsd.dtd">

<webpage id="support-security-patches-3.0">
<config param="desc" value="NetBSD 3.0 Security Advisories"/>
<config param="cvstag" value="$NetBSD: patches-3.0.xml,v 1.12 2008/10/27 20:41:57 adrianp Exp $"/>
<config param="rcsdate" value="$Date: 2008/10/27 20:41:57 $"/>
<head>
<title>NetBSD 3.0 Security Advisories</title>
</head>

<sect1 id="patches-3.0">

<para>
Below is the list of advisories applicable to the
<ulink url="../../releases/formal-3/">NetBSD 3.0</ulink>
release:
</para>

<itemizedlist>
<listitem>A description and resolution procedure for
    ICMPv6 Packet Too Big messages
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-015.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-015</ulink></listitem>
<listitem>A description and resolution procedure for
    Cross-site request forgery in ftpd(8)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-014.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-014</ulink></listitem>
<listitem>A description and resolution procedure for
    IPv6 Neighbor Discovery Protocol
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-013</ulink></listitem>
<listitem>A description and resolution procedure for
    Malicious PPPoE discovery packet can overrun a kernel buffer
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-010</ulink></listitem>
<listitem>A description and resolution procedure for
    BIND cache poisoning
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-009</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL Montgomery multiplication
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-008</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL Multiple issues
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-007</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSH Multiple issues
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-005.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-005</ulink></listitem>
<listitem>A description and resolution procedure for
    bzip2(1) Multiple issues
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-004</ulink></listitem>
<listitem>A description and resolution procedure for
    IPsec in IPv6 Denial of Service
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-003.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-003</ulink></listitem>
<listitem>A description and resolution procedure for
    Endianness issue in fast_ipsec(4)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-002</ulink></listitem>
<listitem>A description and resolution procedure for
    file(1) Integer overflow
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2008-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2008-001</ulink></listitem>
<listitem>A description and resolution procedure for
    BIND cryptographically weak query IDs
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-007.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-007</ulink></listitem>
<listitem>A description and resolution procedure for
    Local panics in display driver code
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-006.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-006</ulink></listitem>
<listitem>A description and resolution procedure for
    IPv6 Type 0 Routing Header
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-005.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-005</ulink></listitem>
<listitem>A description and resolution procedure for
    Insufficient length checking in iso(4)
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-004</ulink></listitem>
<listitem>A description and resolution procedure for
    BIND multiple denial of service vulnerabilities
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-003</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflows in Render and DBE extensions
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-002.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-002</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflow in ktruser()
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2007-001.txt.asc">
    NetBSD Security Advisory NetBSD-SA2007-001</ulink></listitem>
<listitem>A description and resolution procedure for
    libc glob(3) buffer overflow
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-027.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-027</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple denial of service issues
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-026.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-026</ulink></listitem>
<listitem>A description and resolution procedure for
    Multiple information/memory leakage issues
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-025.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-025</ulink></listitem>
<listitem>A description and resolution procedure for
    systrace(4) integer overflow
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-024.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-024</ulink></listitem>
<listitem>A description and resolution procedure for
    OpenSSL RSA Signature Forgery
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-023.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-023</ulink></listitem>
<listitem>A description and resolution procedure for
    BIND recursive query and SIG query processing
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-022.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-022</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflows in CID-keyed font parser
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-021.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-021</ulink></listitem>
<listitem>A description and resolution procedure for
    Integer overflows in PCF font parsers
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-020.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-020</ulink></listitem>
<listitem>A description and resolution procedure for
    Malicious PPP options can overrun a kernel buffer
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-019.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-019</ulink></listitem>
<listitem>A description and resolution procedure for
    sail(6), dm(8) and tetris(6) buffer overflows
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-018.txt.asc">                       
    NetBSD Security Advisory NetBSD-SA2006-018</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail malformed multipart MIME messages
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-017.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-017</ulink></listitem>
<listitem>A description and resolution procedure for                    
    IPv6 socket options can crash the system             
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-016.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-016</ulink></listitem>
<listitem>A description and resolution procedure for                    
    FPU Information leak on i386/amd64/Xen platforms with AMD CPUs             
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-015.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-015</ulink></listitem>
<listitem>A description and resolution procedure for
    An audio subsystem race condition may crash the system
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-014.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-014</ulink></listitem>
<listitem>A description and resolution procedure for
    sysctl(3) local denial of service
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-013.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-013</ulink></listitem>
<listitem>A description and resolution procedure for
    SIOCGIFALIAS ioctl may cause system crash
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-012.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-012</ulink></listitem>
<listitem>A description and resolution procedure for
    IPSec replay attack
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-011.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-011</ulink></listitem>
<listitem>A description and resolution procedure for
    Sendmail race condition
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-010</ulink></listitem>
<listitem>A description and resolution procedure for
    False detection of Intel hardware RNG           
    can be found in                   
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-009.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-009</ulink></listitem>
<listitem>A description and resolution procedure for
    Malformed ELF interpreter causes system crash
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-008.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-008</ulink></listitem>
<listitem>A description and resolution procedure for
    mail(1) creates record file with insecure umask
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-007.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-007</ulink></listitem>
<listitem>A description and resolution procedure for
    bridge memory disclosure
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-005</ulink></listitem>
<listitem>A description and resolution procedure for
    Denial of services issues with pf 
    can be found in
    <ulink url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-004.txt.asc">
    NetBSD Security Advisory NetBSD-SA2006-004</ulink></listitem>
</itemizedlist>

</sect1>
</webpage>

