• [SECURITY] [DSA 3070-1] kfreebsd-9 security update

    From Moritz Muehlenhoff@1:229/2 to All on Fri Nov 7 19:00:02 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3070-1 [email protected] http://www.debian.org/security/ Moritz Muehlenhoff November 07, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : kfreebsd-9
    CVE ID : CVE-2014-3711 CVE-2014-3952 CVE-2014-3953 CVE-2014-8476

    Several vulnerabilities have been discovered in the FreeBSD kernel that
    may lead to a denial of service or information disclosure.

    CVE-2014-3711

    Denial of service through memory leak in sandboxed namei lookups.

    CVE-2014-3952

    Kernel memory disclosure in sockbuf control messages.

    CVE-2014-3953

    Kernel memory disclosure in SCTP. This update disables SCTP, since the
    userspace tools shipped in Wheezy didn't support SCTP anyway.

    CVE-2014-8476

    Kernel stack disclosure in setlogin() and getlogin().

    For the stable distribution (wheezy), these problems have been fixed in
    version 9.0-10+deb70.8.

    We recommend that you upgrade your kfreebsd-9 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBAgAGBQJUXQcdAAoJEBDCk7bDfE42nr0P/2IAF5Nixr8fo6yxraz35ddG CG3b7rnguCi2SBJjGSD2na2VXlNTDMFKjm4NXchLYTJ6qhR8ECWY3+XmcmcwBm/p ceHxo4PmmMMednzkj0qtZbmtyMaeA7pWR7EXSkyX89onzb1UuCNGEgkOi89+jjts JxaE/MeGvezPm9kikkKUAZ0pyRw0TkwyMGXbNVMgbgq3OAyA0XHwMGhX139779oL WiQfMIvxKbBgFxcvEm9BLcc6DZQTj7x2k8f5hTyO89gsnaoTb5jD63owKh//hjLj rWhTkurTaJn5gJ2C3UFlN1XgMkRb7H3l1OKqnIOcvi0EG8vPu4HxDtKi/uSqHu+K 4UDk/KmC1Llafpk7pVJvh5dqc9XxFAepxiNUFD3mZ34EO9Eecf0Qs4SBRH1SRS+F pdtSq6JGhW7aWIHpM/BOjE0CZssRE96wdSqL8AJFvToxtQI+Z14mbUPP4Y33lNlM 4PIjKIAT3TGO+jusvH5IDAkBk4M1Ce9u2AeuoIi0R+dD1u7OgiA5wbSfET2QlZk0 8Mo2URFl/psaVZ7WRbmIXW5eVDmnqIDoDFKgqM9M/Vx+cU7ViT/ZkGTJY06AU1zp HVDfnM9OsUboWcKaphzTARh9PqhREpQAbWCLbp/o0YfLK+e4H6n+UI+OZTtpmWTm jfs/VK7bLDzUPCP0/bfe
    =yvgP
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Benoit Calvez@1:229/2 to All on Fri Nov 7 19:40:03 2014
    XPost: linux.debian.security
    From: [email protected]

    --001a11c20560bce2cc050748ce40
    Content-Type: text/plain; charset=UTF-8
    Content-Transfer-Encoding: quoted-printable

    Le vendredi 7 novembre 2014, Moritz Muehlenhoff <[email protected]> a écrit :

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3070-1 [email protected] <javascript:;>
    http://www.debian.org/security/ Moritz Muehlenhoff November 07, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : kfreebsd-9


    Nous utilisons gnu/Linux sous debian, et pas un Kernel freebsd. Nous ne
    sommes pas concernés pas ce CVE.


    CVE ID : CVE-2014-3711 CVE-2014-3952 CVE-2014-3953 CVE-2014-8476

    Several vulnerabilities have been discovered in the FreeBSD kernel that
    may lead to a denial of service or information disclosure.

    CVE-2014-3711

    Denial of service through memory leak in sandboxed namei lookups.

    CVE-2014-3952

    Kernel memory disclosure in sockbuf control messages.

    CVE-2014-3953

    Kernel memory disclosure in SCTP. This update disables SCTP, since the
    userspace tools shipped in Wheezy didn't support SCTP anyway.

    CVE-2014-8476

    Kernel stack disclosure in setlogin() and getlogin().

    For the stable distribution (wheezy), these problems have been fixed in version 9.0-10+deb70.8.

    We recommend that you upgrade your kfreebsd-9 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected] <javascript:;> -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBAgAGBQJUXQcdAAoJEBDCk7bDfE42nr0P/2IAF5Nixr8fo6yxraz35ddG CG3b7rnguCi2SBJjGSD2na2VXlNTDMFKjm4NXchLYTJ6qhR8ECWY3+XmcmcwBm/p ceHxo4PmmMMednzkj0qtZbmtyMaeA7pWR7EXSkyX89onzb1UuCNGEgkOi89+jjts JxaE/MeGvezPm9kikkKUAZ0pyRw0TkwyMGXbNVMgbgq3OAyA0XHwMGhX139779oL WiQfMIvxKbBgFxcvEm9BLcc6DZQTj7x2k8f5hTyO89gsnaoTb5jD63owKh//hjLj rWhTkurTaJn5gJ2C3UFlN1XgMkRb7H3l1OKqnIOcvi0EG8vPu4HxDtKi/uSqHu+K 4UDk/KmC1Llafpk7pVJvh5dqc9XxFAepxiNUFD3mZ34EO9Eecf0Qs4SBRH1SRS+F pdtSq6JGhW7aWIHpM/BOjE0CZssRE96wdSqL8AJFvToxtQI+Z14mbUPP4Y33lNlM 4PIjKIAT3TGO+jusvH5IDAkBk4M1Ce9u2AeuoIi0R+dD1u7OgiA5wbSfET2QlZk0 8Mo2URFl/psaVZ7WRbmIXW5eVDmnqIDoDFKgqM9M/Vx+cU7ViT/ZkGTJY06AU1zp HVDfnM9OsUboWcKaphzTARh9PqhREpQAbWCLbp/o0YfLK+e4H6n+UI+OZTtpmWTm jfs/VK7bLDzUPCP0/bfe
    =yvgP
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected] <javascript:;>
    with a subject of "unsubscribe". Trouble? Contact
    [email protected] <javascript:;>
    Archive: https://lists.debian.org/[email protected]



    --
    *Benoît CALVEZ*
    *Polyconseil* | 26 rue de Berri | 75008 Paris

    --001a11c20560bce2cc050748ce40
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: quoted-printable

    <br><br>Le vendredi 7 novembre 2014, Moritz Muehlenhoff &lt;<a href="mailto:[email protected]">[email protected]</a>&gt; a écrit :<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">-----BEGIN PGP SIGNED
    MESSAGE-----<br>
    Hash: SHA1<br>

    - -------------------------------------------------------------------------<br> Debian Security Advisory DSA-3070-1                   <a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;[email protected]&#39;)">[email protected]</a><br>
    <a href="http://www.debian.org/security/" target="_blank">http://www.debian.org/security/</a>                        Moritz Muehlenhoff<br>
    November 07, 2014                      <a href="http://www.debian.org/security/faq" target="_blank">http://w