version 1.399, 2002/06/26 11:01:06 |
version 1.400, 2002/06/26 19:07:53 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=modssl></a> |
|
<li><font color=#009000><strong>008: SECURITY FIX: June 26, 2002</strong></font><br> |
|
A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd |
|
module, leading to possible remote crash. |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/008_mod_ssl.patch">A source code patch exists which remedies the problem</a>. |
|
<p> |
<a name=resolver></a> |
<a name=resolver></a> |
<li><font color=#009000><strong>007: SECURITY FIX: June 25, 2002</strong></font><br> |
<li><font color=#009000><strong>007: SECURITY FIX: June 25, 2002</strong></font><br> |
A potential buffer overflow in the DNS resolver has been found.<br> |
A potential buffer overflow in the DNS resolver has been found.<br> |
|
|
<p> |
<p> |
<a name=sshd></a> |
<a name=sshd></a> |
<li><font color=#009000><strong>006: SECURITY FIX: June 24, 2002</strong></font><br> |
<li><font color=#009000><strong>006: SECURITY FIX: June 24, 2002</strong></font><br> |
An (as yet) undisclosed bug exists in OpenSSH, which a patch is not forthcoming |
All versions of OpenSSH's sshd between 2.9.9 and 3.3 contain an input validation |
for yet -- no patch exists yet!<br> |
error that can result in an integer overflow and privilege escalation. |
However, upgrading to <a href="http://www.openssh.com/openbsd.html">OpenSSH 3.3</a> |
This problem is fixed in <a href="http://www.openssh.com/openbsd.html">OpenSSH |
with the <strong>UsePrivilegeSeparation</strong> option enabled will block this |
3.4</a>, and a patch for the vulnerable releases is available as part of the |
problem.<br> |
<a href="http://www.openssh.com/txt/preauth.adv">security advisory</a>. |
All users are advised to update immediately, and keep an eye out for |
<br> |
an upcoming OpenSSH 3.4 release on Monday containing a real fix. |
|
<p> |
<p> |
<a name=httpd></a> |
<a name=httpd></a> |
<li><font color=#009000><strong>005: SECURITY FIX: June 19, 2002</strong></font><br> |
<li><font color=#009000><strong>005: SECURITY FIX: June 19, 2002</strong></font><br> |