Subject: [Security Fix] proplib(3)
To: netbsd current <current-users@netbsd.org>
From: Adrian Portelli <adrianp@NetBSD.org>
List: security-announce
Date: 11/27/2007 20:44:10
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

The NetBSD Security Officer team are aware of various denial of service
(kernel panic) issues in proplib(3).

These vulnerabilities do not exist in the NetBSD 2.x, or 3.x code bases.
 However, NetBSD-current and netbsd-4 were found to be vulnerable to the
issues.

These issues were fixed in the NetBSD-current CVS branch on August 16th
2007 and in the netbsd-4 branch on September 27th 2007.

Users of NetBSD-current and netbsd-4 are advised to update their sources
to get the fixes for these issues.

Thanks To
=========

Jachym Holecek, Matt Fleming, Jason Thorpe and Joerg Sonnenberger for
helping to resolve this.


On behalf of security-officer@,

adrian.


-----BEGIN PGP SIGNATURE-----

iD8DBQFHTIGBLc2rR0mnFJ8RAjKzAKCPuOVp+RLE3DlVD7DKfTeWmS8viwCgljM0
al9bZ/A/tMiCAuvx2reP0CQ=
=QSMN
-----END PGP SIGNATURE-----