From owner-freebsd-questions@FreeBSD.ORG Sat Sep 30 19:40:08 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CE4EF16A412 for ; Sat, 30 Sep 2006 19:40:08 +0000 (UTC) (envelope-from m.seaman@infracaninophile.co.uk) Received: from smtp.infracaninophile.co.uk (happy-idiot-talk.infracaninophile.co.uk [81.187.76.162]) by mx1.FreeBSD.org (Postfix) with ESMTP id C136643D49 for ; Sat, 30 Sep 2006 19:40:07 +0000 (GMT) (envelope-from m.seaman@infracaninophile.co.uk) Received: from [IPv6:::1] (localhost [IPv6:::1]) by smtp.infracaninophile.co.uk (8.13.8/8.13.8) with ESMTP id k8UJdh7k087828; Sat, 30 Sep 2006 20:39:43 +0100 (BST) (envelope-from m.seaman@infracaninophile.co.uk) Authentication-Results: smtp.infracaninophile.co.uk from=m.seaman@infracaninophile.co.uk; sender-id=softfail; spf=softfail X-SenderID: Sendmail Sender-ID Filter v0.2.14 smtp.infracaninophile.co.uk k8UJdh7k087828 Message-ID: <451EC7F8.3040005@infracaninophile.co.uk> Date: Sat, 30 Sep 2006 20:39:36 +0100 From: Matthew Seaman Organization: Infracaninophile User-Agent: Thunderbird 1.5.0.7 (X11/20060915) MIME-Version: 1.0 To: Pascal Bleyler References: <003a01c6e4c4$60fffd30$0500a8c0@voodoo5> In-Reply-To: <003a01c6e4c4$60fffd30$0500a8c0@voodoo5> X-Enigmail-Version: 0.94.0.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------enig9CDB52AEBD407294567CC1B3" X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-2.0.2 (smtp.infracaninophile.co.uk [IPv6:::1]); Sat, 30 Sep 2006 20:40:03 +0100 (BST) X-Virus-Scanned: ClamAV 0.88.4/1952/Sat Sep 30 15:35:55 2006 on happy-idiot-talk.infracaninophile.co.uk X-Virus-Status: Clean X-Spam-Status: No, score=-2.6 required=5.0 tests=BAYES_00, DKIM_POLICY_TESTING, NO_RELAYS autolearn=ham version=3.1.5 X-Spam-Checker-Version: SpamAssassin 3.1.5 (2006-08-29) on happy-idiot-talk.infracaninophile.co.uk Cc: freebsd-questions@freebsd.org Subject: Re: [FreeBSD-Announce] FreeBSD Security AdvisoryFreeBSD-SA-06:23.openssl [REVISED] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 30 Sep 2006 19:40:08 -0000 This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig9CDB52AEBD407294567CC1B3 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: quoted-printable Pascal Bleyler wrote: >> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D >> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D >> FreeBSD-SA-06:23.openssl =20 >> Security Advisory [snip] > I have done these 3 steps already: > # make buildworld > # make buildkernel > # make installkernel >=20 > Do i need to do these steps too? > # mergemaster -p > # make installworld > # mergemaster >=20 > I have FreeBSD 6.1 Release Yes, you absolutely do need to do those steps. The OpenSSL vulnerabilities were in various shared libraries installed as part of the base system. Just replacing the kernel won't do a thing to fix those shlibs. 'make installworld' will, and you need to run mergemaster to keep your /etc files in sync with the rest of the world. Cheers, Matthew --=20 Dr Matthew J Seaman MA, D.Phil. 7 Priory Courtyard Flat 3 PGP: http://www.infracaninophile.co.uk/pgpkey Ramsgate Kent, CT11 9PW --------------enig9CDB52AEBD407294567CC1B3 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (FreeBSD) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFFHsf+8Mjk52CukIwRCJG5AJ42D104Exkhn3M9aJvRU0STij19cgCcD6Pw RDaFM0DOrHSc+6Ffbwptv6E= =sUSo -----END PGP SIGNATURE----- --------------enig9CDB52AEBD407294567CC1B3--