version 1.244, 2000/06/08 17:48:44 |
version 1.245, 2000/06/10 03:43:29 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=isakmpd></a> |
|
<li><font color=#009000><strong>009: SECURITY FIX: June 9, 2000</strong></font><br> |
|
A serious bug in isakmpd(8) policy handling wherein policy |
|
verification could be completely bypassed in isakmpd. |
|
<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/009_isakmpd.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
<a name=msdosfs></a> |
<a name=msdosfs></a> |
<li><font color=#009000><strong>008: RELIABILITY FIX: June 8, 2000</strong></font><br> |
<li><font color=#009000><strong>008: RELIABILITY FIX: June 8, 2000</strong></font><br> |
Some operations in msdosfs could result in a system panic. |
Some operations in msdosfs could result in a system panic. |
|
|
A source code patch exists which remedies this problem.</a> |
A source code patch exists which remedies this problem.</a> |
<p> |
<p> |
<a name=uselogin></a> |
<a name=uselogin></a> |
<li><font color=#009000><strong>006: SECURITY ALERT: June 6, 2000</strong></font><br> |
<li><font color=#009000><strong>006: SECURITY FIX: June 6, 2000</strong></font><br> |
The non-default UseLogin feature in <b>/etc/sshd_config</b> is broken and should not |
The non-default UseLogin feature in <b>/etc/sshd_config</b> is broken and should not |
be used. On other operating systems, it results in a hole.<br> |
be used. On other operating systems, it results in a hole.<br> |
Avoid use of this feature, or update to OpenSSH 2.1.1 or later if you must use it. |
Avoid use of this feature, or update to OpenSSH 2.1.1 or later if you must use it. |