From ac3c57eb536a4ed0013af683ad32ae82a28d8f3b Mon Sep 17 00:00:00 2001 From: gjb Date: Fri, 17 Oct 2014 16:02:34 +0000 Subject: [PATCH] Fill in the security advisories section. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation git-svn-id: svn://svn.freebsd.org/base/releng/10.1@273231 ccf9f872-aa2e-dd11-9fc8-001c23d0bc1f --- .../doc/en_US.ISO8859-1/relnotes/article.xml | 168 +++++++++++++++++- 1 file changed, 167 insertions(+), 1 deletion(-) diff --git a/release/doc/en_US.ISO8859-1/relnotes/article.xml b/release/doc/en_US.ISO8859-1/relnotes/article.xml index 451ade44b..928625938 100644 --- a/release/doc/en_US.ISO8859-1/relnotes/article.xml +++ b/release/doc/en_US.ISO8859-1/relnotes/article.xml @@ -123,7 +123,173 @@ Security Advisories -   + The following security advisories have been issued since + &os; &release.prev;: + + + + + + + + + Advisory + Date + Topic + + + + + + SA-13:14.openssh + 19 November 2013 + OpenSSH AES-GCM memory corruption + vulnerability + + + + SA-14:01.bsnmpd + 14 January 2014 + bsnmpd remote denial of service + vulnerability + + + + SA-14:02.ntpd + 14 January 2014 + ntpd distributed reflection Denial of + Service vulnerability + + + + SA-14:03.openssl + 14 January 2014 + OpenSSL multiple + vulnerabilities + + + + SA-14:04.bind + 14 January 2014 + BIND remote denial of service + vulnerability + + + + SA-14:05.nfsserver + 8 April 2014 + Deadlock in the NFS server + + + + SA-14:06.openssl + 8 April 2014 + OpenSSL multiple + vulnerabilities + + + + SA-14:07.devfs + 30 April 2014 + Fix devfs rules not applied by default for + jails + + + + SA-14:08.tcp + 30 April 2014 + Fix TCP reassembly + vulnerability + + + + SA-14:09.openssl + 30 April 2014 + Fix OpenSSL use-after-free + vulnerability + + + + SA-14:10.openssl + 15 May 2014 + Fix OpenSSL NULL pointer deference + vulnerability + + + + SA-14:11.sendmail + 3 June 2014 + Fix sendmail improper close-on-exec flag + handling + + + + SA-14:13.pam + 3 June 2014 + Fix incorrect error handling in PAM policy + parser + + + + SA-14:14.openssl + 5 June 2014 + Multiple vulnerabilities + + + + SA-14:15.iconv + 24 June 2014 + NULL pointer dereference and out-of-bounds + array access + + + + SA-14:16.file + 24 June 2014 + Multiple vulnerabilities + + + + SA-14:17.kmem + 8 July 2014 + Kernel memory disclosure in control + messages and SCTP notifications + + + + SA-14:18.openssl + 9 September 2014 + Multiple vulnerabilities + + + + SA-14:19.tcp + 16 September 2014 + Denial of Service in TCP packet + processing. + + + + -- 2.42.0