[BACK]Return to errata.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata.html between version 1.399 and 1.400

version 1.399, 2002/06/26 11:01:06 version 1.400, 2002/06/26 19:07:53
Line 49 
Line 49 
 <a name=all></a>  <a name=all></a>
 <li><h3><font color=#e00000>All architectures</font></h3>  <li><h3><font color=#e00000>All architectures</font></h3>
 <ul>  <ul>
   <a name=modssl></a>
   <li><font color=#009000><strong>008: SECURITY FIX: June 26, 2002</strong></font><br>
   A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd
   module, leading to possible remote crash.
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/008_mod_ssl.patch">A source code patch exists which remedies the problem</a>.
   <p>
 <a name=resolver></a>  <a name=resolver></a>
 <li><font color=#009000><strong>007: SECURITY FIX: June 25, 2002</strong></font><br>  <li><font color=#009000><strong>007: SECURITY FIX: June 25, 2002</strong></font><br>
 A potential buffer overflow in the DNS resolver has been found.<br>  A potential buffer overflow in the DNS resolver has been found.<br>
Line 56 
Line 62 
 <p>  <p>
 <a name=sshd></a>  <a name=sshd></a>
 <li><font color=#009000><strong>006: SECURITY FIX: June 24, 2002</strong></font><br>  <li><font color=#009000><strong>006: SECURITY FIX: June 24, 2002</strong></font><br>
 An (as yet) undisclosed bug exists in OpenSSH, which a patch is not forthcoming  All versions of OpenSSH's sshd between 2.9.9 and 3.3 contain an input validation
 for yet -- no patch exists yet!<br>  error that can result in an integer overflow and privilege escalation.
 However, upgrading to <a href="http://www.openssh.com/openbsd.html">OpenSSH 3.3</a>  This problem is fixed in <a href="http://www.openssh.com/openbsd.html">OpenSSH
 with the <strong>UsePrivilegeSeparation</strong> option enabled will block this  3.4</a>, and a patch for the vulnerable releases is available as part of the
 problem.<br>  <a href="http://www.openssh.com/txt/preauth.adv">security advisory</a>.
 All users are advised to update immediately, and keep an eye out for  <br>
 an upcoming OpenSSH 3.4 release on Monday containing a real fix.  
 <p>  <p>
 <a name=httpd></a>  <a name=httpd></a>
 <li><font color=#009000><strong>005: SECURITY FIX: June 19, 2002</strong></font><br>  <li><font color=#009000><strong>005: SECURITY FIX: June 19, 2002</strong></font><br>

Legend:
Removed from v.1.399  
changed lines
  Added in v.1.400