Re: [FreeBSD-Announce] FreeBSD Security AdvisoryFreeBSD-SA-06:23.openssl [REVISED]

2006-09-30 Thread Matthew Seaman
Pascal Bleyler wrote:
>> ==
>> ===
>> FreeBSD-SA-06:23.openssl
>> Security Advisory

[snip]

> I have done these 3 steps already:
> # make buildworld
> # make buildkernel
> # make installkernel
> 
> Do i need to do these steps too?
> # mergemaster -p
> # make installworld
> # mergemaster
> 
> I have FreeBSD 6.1 Release

Yes, you absolutely do need to do those steps.  The OpenSSL
vulnerabilities were in various shared libraries installed as part of
the base system.  Just replacing the kernel won't do a thing to fix
those shlibs.  'make installworld' will, and you need to run mergemaster
to keep your /etc files in sync with the rest of the world.

Cheers,

Matthew

-- 
Dr Matthew J Seaman MA, D.Phil.   7 Priory Courtyard
  Flat 3
PGP: http://www.infracaninophile.co.uk/pgpkey Ramsgate
  Kent, CT11 9PW



signature.asc
Description: OpenPGP digital signature


RE: [FreeBSD-Announce] FreeBSD Security AdvisoryFreeBSD-SA-06:23.openssl [REVISED]

2006-09-30 Thread Pascal Bleyler
HI,

> -Original Message-
> From: [EMAIL PROTECTED] 
> [mailto:[EMAIL PROTECTED] On Behalf Of 
> FreeBSD Security Advisories
> Sent: Friday, September 29, 2006 4:00 PM
> To: FreeBSD Security Advisories
> Subject: [FreeBSD-Announce] FreeBSD Security 
> AdvisoryFreeBSD-SA-06:23.openssl [REVISED]
> 
> 
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
> ==
> ===
> FreeBSD-SA-06:23.openssl
> Security Advisory
>   The 
> FreeBSD Project
> 
> Topic:  Multiple problems in crypto(3)
<..snip..> 
> 1) Upgrade your vulnerable system to 4-STABLE, 5-STABLE, or 
> 6-STABLE, or to the RELENG_6_1, RELENG_6_0, RELENG_5_5, 
> RELENG_5_4, RELENG_5_3, or RELENG_4_11 security branch dated 
> after the correction date.
> 
> 2) To patch your present system:
> 
> The following patch has been verified to apply to FreeBSD 
> 4.11, 5.3, 5.4, 5.5, 6.0, and 6.1 systems.
> 
> a) Download the patch from the location below, and verify the 
> detached PGP signature using your PGP utility.
> 
> # fetch http://security.FreeBSD.org/patches/SA-06:23/openssl.patch
> # fetch http://security.FreeBSD.org/patches/SA-06:23/openssl.patch.asc
> b) Execute the following commands as root:
> 
> # cd /usr/src
> # patch < /path/to/patch
> 
> c) Recompile the operating system as described in
> http://www.freebsd.org/handbook/makeworld.html> and 
> reboot the system.


I have done these 3 steps already:
# make buildworld
# make buildkernel
# make installkernel

Do i need to do these steps too?
# mergemaster -p
# make installworld
# mergemaster

I have FreeBSD 6.1 Release

Thanks for your help
Pascal Bleyler

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"