Security Officer-supported branches update

From: Colin Percival (cperciva_at_freebsd.org)
Date: 03/05/04

  • Next message: Dag-Erling Smørgrav: "Re: Security Officer-supported branches update"
    Date: Fri, 5 Mar 2004 01:30:35 -0800
    To: security@freebsd.org
    
    

    The FreeBSD Security Officer would normally be sending out this email,
    but he's a bit busy right now and it is clear from reactions to FreeBSD
    Security Advisory FreeBSD-SA-04:04.tcp that many people are unaware of
    the current status of the RELENG_5_1 branch, so I'm going to send out
    this reminder myself.

    The branches supported by the FreeBSD Security Officer have been
    updated to reflect the recent EoL (end-of-life) of FreeBSD 5.1. The
    new list is below and at <URL: http://www.freebsd.org/security/ >.

    If you are running FreeBSD 4.7 or older, or FreeBSD 5.0 or 5.1, and
    you wish to be certain to get critical bug fixes, it is recommended
    that you upgrade to one of the newer security branches.

    [Excerpt from http://www.freebsd.org/security/]

    FreeBSD Security Advisories

       The FreeBSD Security Officer provides security advisories for
       several branches of FreeBSD development. These are the -STABLE
       Branches and the Security Branches. (Advisories are not issued for
       the -CURRENT Branch.)

         * There is usually only a single -STABLE branch, although during
           the transition from one major development line to another
           (such as from FreeBSD 4.x to 5.x), there is a time span in
           which there are two -STABLE branches. The -STABLE branch tags
           have names like RELENG_4. The corresponding builds have names
           like FreeBSD 4.6-STABLE.

         * Each FreeBSD Release has an associated Security Branch. The
           Security Branch tags have names like RELENG_4_6. The
           corresponding builds have names like FreeBSD 4.6-RELEASE-p7.

       Each branch is supported by the Security Officer for a limited
       time only, typically through 12 months after the release. The
       estimated lifetimes of the currently supported branches are given
       below. The Estimated EoL (end-of-life) column gives the earliest
       date on which that branch is likely to be dropped. Please note
       that these dates may be extended into the future, but only
       extenuating circumstances would lead to a branch's support being
       dropped earlier than the date listed.

       +------------------------------------------+
       | Branch | Release | Estimated EoL |
       |----------+-------------+-----------------|
       |RELENG_4 |n/a |October 31, 2004 |
       |----------+-------------+-----------------|
       |RELENG_4_8|4.8-RELEASE |March 31, 2004 |
       |----------+-------------+-----------------|
       |RELENG_4_9|4.9-RELEASE |October 31, 2004 |
       |----------+-------------+-----------------|
       |RELENG_5_2|5.2.1-RELEASE|July 31, 2004 |
       +------------------------------------------+

       Older releases are not maintained and users are strongly
       encouraged to upgrade to one of the supported releases mentioned
       above.

    Colin Percival (wearing member-of-secteam hat)

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Dag-Erling Smørgrav: "Re: Security Officer-supported branches update"

    Relevant Pages

    • Re: SSHD
      ... When I try to open PGP signed stuff from the FreeBSD Security Officer, ... >> I meticulosly closed most of the TCP ports to close all security holes, ... >> I replaced telnet with sshd, and now I was wondering if there were any ...
      (FreeBSD-Security)
    • Re: [security-advisories@freebsd.org: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-03:17.
      ... >> I'm finally motivated to ask, why don't security advisories contain ... > Simply because the SO does not support -CURRENT. ... Does this mean that the situation can ever arise where a security bug ... To unsubscribe, ...
      (freebsd-current)
    • FW: {RTCProd#003-520-317}Windows Update Support Request
      ... support policy for Windows NT 4.0 Workstation SP6a. ... The Microsoft Support Lifecycle defines the support policies for all ... This means that after this date, Microsoft would no longer create ... security fixes for this platform, nor automatically post to WU, etc. ...
      (NT-Bugtraq)
    • RE: Vendor wants remote control of our Servers and Workstations
      ... Of course the age-old problem with security is that ... Vendor has significant access to your internal ... this vendor uses the same method to support a number ... customer and makes significant changes ... ...
      (Security-Basics)
    • Re: The Register: OpenVMS among most-secure of operating systems
      ... >story with out of support versions of VMS/OpenVMS as well. ... >Take LAND there is no CERT advisory for LAND refering to ... You have claimed that CERT advisory counts is ... not a good measure of the relative security of a system. ...
      (comp.os.vms)