version 1.463, 2003/11/04 16:01:21 |
version 1.464, 2003/11/10 04:36:49 |
|
|
<li><font color="#009000"><strong>005: RELIABILITY FIX: November 4, 2003</strong></font><br> |
<li><font color="#009000"><strong>005: RELIABILITY FIX: November 4, 2003</strong></font><br> |
It is possible for a local user to cause a system panic by executing a specially crafted binary with an invalid header. |
It is possible for a local user to cause a system panic by executing a specially crafted binary with an invalid header. |
<br> |
<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch">A source code patch exists which remedies the problem</a>.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/005_exec.patch"> |
|
A source code patch exists which remedies the problem</a>.<br> |
<p> |
<p> |
<a name=httpd></a> |
<a name=httpd></a> |
<li><font color="#009000"><strong>004: RELIABILITY FIX: November 1, 2003</strong></font><br> |
<li><font color="#009000"><strong>004: RELIABILITY FIX: November 1, 2003</strong></font><br> |
|
|
or potentially run arbitrary code as the user <tt>www</tt> (although it |
or potentially run arbitrary code as the user <tt>www</tt> (although it |
is believed that ProPolice will prevent code execution). |
is believed that ProPolice will prevent code execution). |
<br> |
<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/004_httpd.patch">A source code patch exists which remedies the problem</a>.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/004_httpd.patch"> |
|
A source code patch exists which remedies the problem</a>.<br> |
<p> |
<p> |
<a name=arp></a> |
<a name=arp></a> |
<li><font color="#009000"><strong>003: RELIABILITY FIX: November 1, 2003</strong></font><br> |
<li><font color="#009000"><strong>003: RELIABILITY FIX: November 1, 2003</strong></font><br> |
It is possible for a local user to cause a system panic by flooding it with spoofed ARP |
It is possible for a local user to cause a system panic by flooding it with spoofed ARP |
requests.<br> |
requests.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/003_arp.patch">A source code patch exists which remedies the problem</a>.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/003_arp.patch"> |
|
A source code patch exists which remedies the problem</a>.<br> |
<p> |
<p> |
<a name=asn1></a> |
<a name=asn1></a> |
<li><font color="#009000"><strong>002: SECURITY FIX: November 1, 2003</strong></font><br> |
<li><font color="#009000"><strong>002: SECURITY FIX: November 1, 2003</strong></font><br> |
|
|
attacker to mount a denial of service attack against applications linked with |
attacker to mount a denial of service attack against applications linked with |
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=3">ssl(3)</a>. |
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=3">ssl(3)</a>. |
This does not affect OpenSSH.<br> |
This does not affect OpenSSH.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/002_asn1.patch">A source code patch exists which remedies the problem</a>.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/002_asn1.patch"> |
|
A source code patch exists which remedies the problem</a>.<br> |
<p> |
<p> |
<a name=cd_booklet></a> |
<a name=cd_booklet></a> |
<li><font color="#009000"><strong>001: DOCUMENTATION FIX: November 1, 2003</strong></font><br> |
<li><font color="#009000"><strong>001: DOCUMENTATION FIX: November 1, 2003</strong></font><br> |