===================================================================== CERT-Renater Note d'Information No. 2005/VULN574 _____________________________________________________________________ DATE : 27/09/2005 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : NetBSD. ====================================================================== " On behalf of the NetBSD Release Engineering team, I'm happy to announce the availability of NetBSD 2.1 RC5 for testing. (A security issue came up shortly after RC4 was tagged, so it was never announced). NetBSD 2.1 RC5 is available in the "daily builds" section of your local FTP mirror (in the /pub/NetBSD-daily/netbsd-2-1-RC5 directory on most mirrors), and we encourage you to test it out and report any bugs using send-pr(1). We anticipate that this will be the final release candidate for NetBSD 2.1, barring any major issues or security problems. Here is a brief summary of changes from NetBSD 2.1_RC3 to 2.1_RC4: - protect ipsec ioctls from negative offsets - fix the 'postinstall' phase of sysinst - update to tzdata2005m (includes US DST changes for 2007) - Avoid an infinite loop in gzip decompressing invalid files - Avoid panic trying to write files to msdosfs of 4GB or greater - remove an unsafe /tmp file creation in X - add a missing range check in FreeBSD compat code - add missing bootxx_ffsv2 to amd64 bootfloppies - Initialize CP0 pagemask register properly on mips - make /usr/bin/which return a proper error indicator - add freebsd_sched.c when building compat_freebsd as an LKM - various minor sysinst fixes and language improvements - fixes for the sk(4) driver to make dhclient work better - kqueue: EOF on pipe gains no EVFILT_READ event - fix - Update the OpenBlockS266 support Here is a brief summary of changes from NetBSD 2.1_RC4 to 2.1_RC5: - fix security hole reported in CAN-2005-2495 " ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================