> For the complete documentation index, see [llms.txt](https://book.bsdcn.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://book.bsdcn.org/release/freebsd-5.4-release/5.4-errata.md).

# FreeBSD 5.4-RELEASE 勘误

**FreeBSD 项目**

版权所有 © 2000, 2001, 2002, 2003, 2004, 2005, 2006 FreeBSD 文档项目

```ini
$FreeBSD: src/release/doc/en_US.ISO8859-1/errata/article.sgml,v 1.69.2.32 2006/02/05 20:45:04 bmah Exp $
```

FreeBSD 是 FreeBSD 基金会的注册商标。

Intel、Celeron、EtherExpress、i386、i486、Itanium、Pentium 和 Xeon 是 Intel Corporation 或其子公司在美国及其他国家的商标或注册商标。

Sparc、Sparc64、SPARCEngine 和 UltraSPARC 是 SPARC International, Inc 在美国及其他国家的商标。带有 SPARC 商标的产品基于 Sun Microsystems, Inc. 开发的架构。

许多制造商和销售商用于区分其产品的名称被主张为商标。在本文件中出现这些名称时，如果 FreeBSD 项目知道该商标的主张，就会在名称后附上“™”或“®”符号。

本文档列出了 FreeBSD 5.4-RELEASE 的勘误项，包含发行后才发现或发行周期后期才确定而未能纳入发行文档的重要信息。这些信息包括安全公告，以及与可能影响其运行或可用性的软件或文档相关的消息。在安装此版本 FreeBSD 之前，应始终查阅本文档的最新版本。

FreeBSD 5.4-RELEASE 的勘误文档将维护至 FreeBSD 5.5-RELEASE 发布。

## 1 引言

本勘误文档包含有关 FreeBSD 5.4-RELEASE 的“最新消息”。在安装此版本之前，请务必查阅本文档，以了解发行后才发现的或已经发现并修复的问题。

随发行版实际分发的任何勘误文档（例如 CDROM 发行版中的）按定义已过时，但其他副本会在互联网上保持更新，应作为此版本的“当前勘误”查阅。这些其他勘误副本位于 [http://www.FreeBSD.org/releases/](http://www.freebsd.org/releases/)，以及任何保持此位置最新镜像的站点。

FreeBSD 5-STABLE 的源代码和二进制快照也包含本文档的最新副本（截至快照时的版本）。

有关所有 FreeBSD CERT 安全公告的列表，请参见 [http://www.FreeBSD.org/security/](http://www.freebsd.org/security/) 或 [ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/)。

## 2 安全公告

以下安全公告适用于 FreeBSD 5.4-RELEASE。更多信息，请参阅 [ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/) 上的各个公告。

| 公告                                                                                                 | 日期              | 主题                                                                                                           |
| -------------------------------------------------------------------------------------------------- | --------------- | ------------------------------------------------------------------------------------------------------------ |
| [06:07.pf](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:07.pf.asc)              | 2006 年 1 月 25 日 | [pf(4)](https://man.freebsd.org/cgi/man.cgi?query=pf\&sektion=4\&manpath=FreeBSD+5.4-RELEASE) 中的 IP 分片处理导致崩溃 |
| [06:03.cpio](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.asc)          | 2006 年 1 月 11 日 | [cpio(1)](https://man.freebsd.org/cgi/man.cgi?query=cpio\&sektion=1\&manpath=FreeBSD+5.4-RELEASE) 中的多个漏洞     |
| [06:02.eex](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc)             | 2006 年 1 月 11 日 | [ee(1)](https://man.freebsd.org/cgi/man.cgi?query=ee\&sektion=1\&manpath=FreeBSD+5.4-RELEASE) 临时文件权限提升       |
| [06:01.texindex](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:01.texindex.asc)  | 2006 年 1 月 11 日 | Texindex 临时文件权限提升                                                                                            |
| [SA-05:09.htt](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:09.htt.asc)         | 2005 年 5 月 22 日 | 使用 HTT 时的信息泄露                                                                                                |
| [SA-05:10.tcpdump](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:10.tcpdump.asc) | 2005 年 6 月 9 日  | tcpdump 协议解码中的无限循环                                                                                           |
| [SA-05:11.gzip](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:11.gzip.asc)       | 2005 年 6 月 9 日  | gzip 目录遍历和权限竞争漏洞                                                                                             |
| [SA-05:13.ipfw](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:13.ipfw.asc)       | 2005 年 6 月 29 日 | ipfw 使用地址表时的数据包匹配错误                                                                                          |
| [SA-05:14.bzip2](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:14.bzip2.asc)     | 2005 年 6 月 29 日 | bzip2 拒绝服务和权限竞争漏洞                                                                                            |
| [SA-05:15.tcp](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc)         | 2005 年 6 月 29 日 | TCP 连接阻塞拒绝服务                                                                                                 |
| [SA-05:16.zlib](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:16.zlib.asc)       | 2005 年 7 月 6 日  | zlib 中的缓冲区溢出                                                                                                 |
| [SA-05:17.devfs](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:17.devfs.asc)     | 2005 年 7 月 20 日 | devfs 规则集绕过                                                                                                  |
| [SA-05:18.zlib](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:18.zlib.asc)       | 2005 年 7 月 27 日 | zlib 中的缓冲区溢出                                                                                                 |
| [SA-05:19.ipsec](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:19.ipsec.asc)     | 2005 年 7 月 27 日 | IPsec 在 AES-XCBC-MAC 中使用错误密钥                                                                                 |

## 3 未解决问题

无问题。

## 4 最新消息

（2005 年 5 月 6 日）**/dev/iir** 设备节点的默认权限存在错误，允许非特权本地用户向 [iir(4)](https://man.freebsd.org/cgi/man.cgi?query=iir\&sektion=4\&manpath=FreeBSD+5.4-RELEASE) 驱动程序支持的硬件发送命令。此错误在 5.4-RELEASE 之前修复完成，但修复时间太晚，未能纳入发行说明。更多信息请参阅安全公告 [FreeBSD-SA-05:06.iir](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:06.iir.asc)。

（2005 年 5 月 6 日）修复了 [i386\_get\_ldt(2)](https://man.freebsd.org/cgi/man.cgi?query=i386_get_ldt\&sektion=2\&manpath=FreeBSD+5.4-RELEASE) 系统调用输入参数验证中的一个 bug，该 bug 可能导致内核内存泄露给用户进程。此 bug 在 5.4-RELEASE 之前修复完成，但未及时纳入发行说明。更多信息请参阅安全公告 [FreeBSD-SA-05:07.ldt](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:07.ldt.asc)。

（2005 年 5 月 6 日）FreeBSD 5.4-RELEASE 修复了内核各部分中的多个信息泄露漏洞，但修复时间太晚，未能纳入发行说明。更多信息请参阅安全公告 [FreeBSD-SA-05:08.kmem](ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:08.kmem.asc)。

（2005 年 6 月 24 日）FreeBSD/sparc64 5.4-RELEASE 本应说明：在即将到来的 6.0-RELEASE 之前，FreeBSD/sparc64 GENERIC 内核仅官方支持串行控制台。对于 FreeBSD/sparc64 5.4-RELEASE GENERIC 内核尤其如此，因为也为图形控制台提供有限间接支持的 ofw\_console(4) 驱动程序已被 [uart(4)](https://man.freebsd.org/cgi/man.cgi?query=uart\&sektion=4\&manpath=FreeBSD+5.4-RELEASE) 驱动程序替换，以获得更好的串行支持。

由于这一串行控制台限制，尝试将 FreeBSD/sparc64 5.4-RELEASE GENERIC 内核与图形控制台一起使用时，在显示“`jumping to kernel entry at...`”消息后，屏幕将停止工作，而 FreeBSD 本身实际上仍在继续运行。

如果你仍想使用 FreeBSD/sparc64 图形控制台，可以执行以下操作之一：

* 如果你的机器配备了 Sun Creator、Sun Creator3D 或 Sun Elite3D 帧缓冲卡和 Sun RS232 键盘，你可以使用串行控制台安装 FreeBSD/sparc64 5.4-RELEASE，然后编译带有以下附加选项的定制内核：

  ```sh
  device          sc
  device          creator
  options         KBD_INSTALL_CDEV
  ```

  此外，你必须在 **/etc/ttys** 中启用 `tty[1-7]` 条目，如下所示：

  ```sh
  ttyv0   "/usr/libexec/getty Pc"         cons25  on  secure
  # 虚拟终端
  ttyv1   "/usr/libexec/getty Pc"         cons25  on  secure
  ttyv2   "/usr/libexec/getty Pc"         cons25  on  secure
  ttyv3   "/usr/libexec/getty Pc"         cons25  on  secure
  ttyv4   "/usr/libexec/getty Pc"         cons25  on  secure
  ttyv5   "/usr/libexec/getty Pc"         cons25  on  secure
  ttyv6   "/usr/libexec/getty Pc"         cons25  on  secure
  ttyv7   "/usr/libexec/getty Pc"         cons25  on  secure
  ```

  这将使这些键盘和帧缓冲卡获得原生支持，包括 VTY 切换和 X Window 系统。请注意，这至少需要 FreeBSD/sparc64 5.4-RELEASE，否则在大多数 UltraSPARC 型号上将无法工作。
* 如果你的机器配备了 ATI Mach64 帧缓冲卡（例如 Sun Blade 100/150 和 Sun Ultra 5/10 板载，以及 Sun PGX8 和 Sun PGX64 附加卡）或 PS/2 或 USB 键盘，请更新至 2005 年 6 月 10 日或之后的 FreeBSD/sparc64 6.0。如果使用其中的标准 GENERIC 内核和 **/etc/ttys**，则无需进一步操作。

  这将使这些键盘和帧缓冲卡获得原生支持，包括 VTY 切换和 X Window 系统。
* 如果你的机器配备了上述未提及的硬件，或你拒绝更新至 FreeBSD/sparc64 6.0，作为最后手段你可以重新启用 ofw\_console(4) 驱动程序。为此，请构建带有以下附加选项的定制内核：

  ```sh
  device          ofw_console
  device          sab
  device          zs
  ```

  并确保注释掉以下内核选项：

  ```sh
  device          uart
  ```

  这将为任何图形控制台硬件提供有限的间接支持，但性能较差，且 VTY 切换和 X Window 系统无法工作。请注意，ofw\_console(4) 并非真正的 MPSAFE，因此在某些条件下可能导致崩溃。

有关重新编译内核或更新至 FreeBSD 6.0 的更多详情，请分别参阅 FreeBSD 手册中的 [配置 FreeBSD 内核](http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html) 和 [前沿](http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/cutting-edge.html) 章节。

***

本文件及其他与发行相关的文档可从 [http://www.FreeBSD.org/snapshots/](http://www.freebsd.org/snapshots/) 下载。

如有关于 FreeBSD 的问题，请先阅读 [文档](http://www.freebsd.org/docs.html)，再联系 <questions@FreeBSD.org>。

所有 FreeBSD 5-STABLE 用户应订阅 <stable@FreeBSD.org> 邮件列表。

如有关于此文档的问题，请发送电子邮件至 <doc@FreeBSD.org>。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://book.bsdcn.org/release/freebsd-5.4-release/5.4-errata.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
