The NetBSD development team have announced the release of the second "critical/security" update of the 5.0 release branch, NetBSD 5.0.2. The latest maintenance release includes a number of important security and stability fixes for the BSD based operating system.. NetBSD 5.0.2 features two fixes related to security advisories, including an issue in the OpenSSL Transport Layer Security (TLS) session renegotiation that could allow an attacker to remotely intercept communication. The developers have disabled TLS session renegotiation in order to prevent Man-in-the-Middle attacks. The second advisory fix corrects an issue that could allow a local attacker to invoke a kernel panic due to issues in the azalia(4) and hdaudio(4) drivers. The link for this article located at H Security is no longer available. . NetBSD 5.0.2 introduces essential patches for OpenSSL SSL concerns and safeguards against kernel crash exploits within audio components.. NetBSD Update, OpenSSL Fixes, Kernel Issues, NetBSD Security, TLS Vulnerability. . LinuxSecurity.com Team
Sun Microsystems has issued a security update intended for computers running Sun Solaris 10 operating system. The update patches a security vulnerability that could cause kernel panic by sending one false ICMP request. The vendor does not disclose the conditions required for the attack to occur, but in its security advisory, Sun suggest testing whether a system responds to ICMP echo requests using a normal ping utility. . The link for this article located at ITObserver is no longer available. . An essential security patch for Sun Solaris 10 resolves a kernel crash flaw triggered by a harmful ICMP message.. Sun Solaris, ICMP request, Kernel panic, Security update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.