Re: cpu-microcode-intel-20231114

2024-04-15 Thread Martin Simmons
> On Mon, 15 Apr 2024 09:09:57 +, =?iso-8859-2?Q?Marek Anio=B3a?= said: > > As of 13 March 2024. "pkg audit" reports the following vulnerabilities in > FreeBSD 13.3-RELEASE-p1: > > cpu-microcode-intel-20231114 is vulnerable: >   Intel processors - multiple vulnerabilities >   CVE: CVE-20

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-11 Thread Martin Simmons
>>>>> On Fri, 11 Dec 2020 13:28:43 +0100, Franco Fichtner said: > > > On 11. Dec 2020, at 13:20, Martin Simmons wrote: > > > >  > >> > >>>>>> On Fri, 11 Dec 2020 12:44:17 +0100, Franco Fichtner said: > &

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-11 Thread Martin Simmons
>>>>> On Fri, 11 Dec 2020 12:44:17 +0100, Franco Fichtner said: > > > On 11. Dec 2020, at 12:38 PM, Martin Simmons wrote: > > > >>>>>> On Thu, 10 Dec 2020 22:46:28 -0800, John-Mark Gurney said: > >> > >> What are peoples tho

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-11 Thread Martin Simmons
> On Wed, 9 Dec 2020 23:03:00 + (UTC), FreeBSD Security Advisories > said: > > Note: The OpenSSL project has published publicly available patches for > versions included in FreeBSD 12.x. This vulnerability is also known to > affect OpenSSL versions included in FreeBSD 11.4. However

Re: FreeBSD Security Advisory FreeBSD-SA-20:33.openssl

2020-12-11 Thread Martin Simmons
> On Thu, 10 Dec 2020 22:46:28 -0800, John-Mark Gurney said: > > What are peoples thoughts on how to address the support mismatch between > FreeBSD and OpenSSL? And how to address it? Maybe it would help a little if the packages on pkg.FreeBSD.org all used the pkg version of OpenSSL? Curren

Re: Malicious URL ? https://[::]/

2018-01-25 Thread Martin Simmons
> On Wed, 24 Jan 2018 12:02:47 -0800 (PST), Roger Marquis said: > > Another intermediate URL-checker reports that the plugin in question > (CanvasBlocker) is requesting https://[::]/ directly. If a bug this is > the first I've seen of it's kind. If not the question is what threat > profile [

Re: FreeBSD Security Advisory FreeBSD-SA-16:33.openssh

2016-11-02 Thread Martin Simmons
> On Wed, 2 Nov 2016 07:55:33 + (UTC), FreeBSD Security Advisories > said: > > = > FreeBSD-SA-16:33.opensshSecurity Advisory >

Re: ftpd leaks info which might be useful to an attacker

2016-09-14 Thread Martin Simmons
> On Tue, 13 Sep 2016 14:07:09 -0700, Ronald F Guilmette said: > > I've been moving all of my stuff over to a shiny new VM that I've > purchased, and in the process I am having to revisit various > configuration decisions I made 10 years ago or more. > > One set of such decisions has to do wi

Re: Unexplained update to /boot/boot1.efi and 2 others by freebsd-update

2016-08-26 Thread Martin Simmons
>>>>> On Mon, 22 Aug 2016 17:28:21 -0700, Gleb Smirnoff said: > > Martin, > > On Mon, Aug 22, 2016 at 03:15:47PM +0100, Martin Simmons wrote: > M> Running freebsd-update to convert 10.1-RELEASE-p36 to -p37 updates 3 efi > files > M> in /boot,

Unexplained update to /boot/boot1.efi and 2 others by freebsd-update

2016-08-22 Thread Martin Simmons
Running freebsd-update to convert 10.1-RELEASE-p36 to -p37 updates 3 efi files in /boot, but they are not mentioned in any security advisory or errata notice that I can find and no corresponding source files are updated. This is repeatable on several unrelated systems so I don't think my files hav

Re: FreeBSD-EN-16:06

2016-05-06 Thread Martin Simmons
> On Sat, 7 May 2016 00:56:34 +1000 (EST), Ian Smith said: > > On Fri, 6 May 2016 09:58:06 -0400, Robert Ames wrote: > > > This directory seems to be empty. > > > > https://security.FreeBSD.org/patches/EN-16:06 > > > Like that, yes. > > >From the