Re: TCP timestamp vulnerability

From: Jacques Vidrine (nectar_at_FreeBSD.org)
Date: 05/23/05

  • Next message: Fernando Gleiser: "Re: How to setup IPSec tunnel between FreeBSD and Linux systems...?"
    Date: Mon, 23 May 2005 11:27:12 -0500
    To: Christian Brueffer <chris@unixpages.org>
    
    
    

    On May 19, 2005, at 5:53 AM, Christian Brueffer wrote:

    > Hi,
    >
    > fixes for the vulnerability described in http://www.kb.cert.org/
    > vuls/id/637934
    > were checked in to CURRENT and RELENG_5 by ps in April.
    >
    > http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet/tcp_input.c
    >
    > Revisions 1.270 and 1.252.2.16
    >
    > He didn't commit it to RELENG_5_4 for some reason, so 5.4 shipped with
    > it.
    >
    > My guess is that he didn't notify you guys either.
    >
    > I stumbled upon this through a Heise News article at
    > http://www.heise.de/newsticker/meldung/59672. Sent them an update
    > about
    > the fixed branches, but they'd like to know why this wasn't
    > communicated
    > back to US-CERT yadda yadda yadda.

    Thanks, Christian. No, ps@ didn't point it out. It gets a little
    confusing too, since I see that the work was submitted by multiple
    folks, one of which reported another related vulnerability to us on
    May 18 (7 days after that commit). Now to try to untangle what is
    what ...

    -- 
    Jacques A Vidrine / NTT/Verio
    nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org
    
    



  • Next message: Fernando Gleiser: "Re: How to setup IPSec tunnel between FreeBSD and Linux systems...?"

    Relevant Pages

    • Re: More On NSA Intel
      ... > [yadda yadda yadda deleted] ... The inexorable encroachment of federal power into our rights. ... denying states medical marijuana yet allowing assisted suicide. ... I wish AIDS on these folks. ...
      (rec.sport.football.college)
    • Re: Reward for Joe Bachmann recovery. Last Attempt !!!!!!!
      ... Does he mean not mad as hell, cause folks sure have a right to be. ... Arcadefreaque wrote: ... yadda yadda yadda.. ...
      (rec.games.video.arcade.collecting)