version 1.297, 2000/12/19 20:17:57 |
version 1.298, 2000/12/19 20:43:50 |
|
|
<ul> |
<ul> |
<a name=procfs></a> |
<a name=procfs></a> |
<li><font color=#009000><strong>013: SECURITY FIX: Dec 18, 2000</strong></font><br> |
<li><font color=#009000><strong>013: SECURITY FIX: Dec 18, 2000</strong></font><br> |
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=mount_procfs&sektion=8">procfs</a> contained numerous overflows, which could lead an intruder to root permissions. Procfs is NOT enabled by default in OpenBSD. <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/013_procfs.patch">A source code patch exists which remedies the problem.</a> |
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=mount_procfs&sektion=8">Procfs</a> contained numerous overflows, which could lead an intruder to root permissions. Procfs is NOT enabled by default in OpenBSD. <br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/013_procfs.patch">A source code patch exists which remedies the problem.</a> |
|
<p> |
<a name=hwcrypto></a> |
<a name=hwcrypto></a> |
<li><font color=#009000><strong>011: RELIABILITY FIX: Dec 13, 2000</strong></font><br> |
<li><font color=#009000><strong>011: RELIABILITY FIX: Dec 13, 2000</strong></font><br> |
The crypto subsystem could incorrectly fail to run certain software ciphers, |
The crypto subsystem could incorrectly fail to run certain software ciphers, |
|
|
OpenBSD 2.8's ftpd contains a one-byte overflow in the replydirname() function.<br> |
OpenBSD 2.8's ftpd contains a one-byte overflow in the replydirname() function.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/005_ftpd.patch"> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/005_ftpd.patch"> |
A source code patch exists which remedies the problem.</a><br> |
A source code patch exists which remedies the problem.</a><br> |
|
You can view the <a href="advisories/ftpd_replydirname.txt">OpenBSD Advisory</a> here. |
<p> |
<p> |
<a name=rijndael> </a> |
<a name=rijndael> </a> |
<li><font color=#009000><strong>004: RELIABILITY FIX: Nov 17, 2000</strong></font><br> |
<li><font color=#009000><strong>004: RELIABILITY FIX: Nov 17, 2000</strong></font><br> |