Re: Patch/Announcement for DHCPD remote root hole?

From: Jacques A. Vidrine (nectar@FreeBSD.org)
Date: 05/16/02


Date: Thu, 16 May 2002 12:45:58 -0500
From: "Jacques A. Vidrine" <nectar@FreeBSD.org>
To: Matt Piechota <piechota@argolis.org>

On Thu, May 16, 2002 at 12:49:11AM -0400, Matt Piechota wrote:
> That's why they're not required to cvsup to get patches. Do you even read
> the Security Notices? They include links to get individual patches. You
> can click on them even, at least I assume you can in Eudora.

There are also some very new, experimental `cumulative patches' here:

4.5-RELEASE-p4
  http://people.freebsd.org/~nectar/secupd-4.5-bin-4.tgz
  http://people.freebsd.org/~nectar/secupd-4.5-sys-4.tgz
  http://people.freebsd.org/~nectar/secupd-4.5-src-4.tgz

4.5-RELEASE-p5
  http://people.freebsd.org/~nectar/secupd-4.5-bin-5.tgz
  http://people.freebsd.org/~nectar/secupd-4.5-sys-5.tgz
  http://people.freebsd.org/~nectar/secupd-4.5-src-5.tgz

These are experimental, not signed, may blow up your system, install
trojan horses, cause hair loss, and so on. We do need some feedback on
them, however.

Some notes: You need only apply the latest patch. You can skip
patches. Each patch contains all previous patches. This is to
make it possible to update from one patch level to another using
portupgrade and other such tools. If you want to see what happens
when installing `over' another patch, or deinstalling an old one, or
using portupgrade, then you'll want both the p4 and p5 patches.
Otherwise, you just want p5.

These only apply to 4.5-RELEASE* systems.

The `bin' packages are the actual binaries.
The `sys' packages are updated sources for src/sys -- they are supplied
to allow you to recompile your kernel.
The `src' packages include all updated sources not in src/sys.

Have fun,

-- 
Jacques A. Vidrine <n@nectar.cc>                     http://www.nectar.cc/
NTT/Verio SME           .      FreeBSD UNIX      .        Heimdal Kerberos
jvidrine@verio.net      .   nectar@FreeBSD.org   .           nectar@kth.se
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • 9_Recommended error codes (specifically return code 5)
    ... * "return code 2" indicates patches are already installed. ... * "return code 25" means a patches requires another patch that is not yet installed. ... With or without using the save option, the patch installation process ... Installing 114008-01... ...
    (SunManagers)
  • Re: This is [Re:] How to improve the quality of the kernel[?].
    ... The -mm kernel already implements what your proposed PTS would do. ... If patch have no TS ID, ... Thus i can apply for example lguest patches and implement and test new ... How many open source projects use Bugzilla and how many use the Debian BTS? ...
    (Linux-Kernel)
  • Re: ATTACK of the WEEK-fentanyl patches
    ... FDA warns of deaths from fentanyl patch ... Some of the deaths came after doctors prescribed the patches to the ... The drug is only for chronic pain in people used to narcotics, ...
    (alt.support.chronic-pain)
  • Tru64 and OpenVMS patch announcements change after next month
    ... distribution of various patches ... OpenVMS systems with DCE and/or RPC installed. ... Update on OpenVMS and Tru64 UNIX Patches in HP ITRC ... Tru64 patch server will soon be shutdown. ...
    (Bugtraq)
  • Re: Conflicting info between the global Security Bulletin and some SPi Security Bulletin
    ... The MS02-050 is explicitly listed as included in SP4 AND in Rollup 1 ... I think the correct answer is that it depends on the era of the patch. ... installers do not always use such ... patches later than the end of 2002 are ...
    (microsoft.public.win2000.security)