Return to errata.html CVS log | Up to [local] / www |
version 1.461, 2003/10/31 01:54:54 | version 1.462, 2003/10/31 21:31:35 | ||
---|---|---|---|
|
|
||
<li><h3><font color="#e00000">All architectures</font></h3> | <li><h3><font color="#e00000">All architectures</font></h3> | ||
<ul> | <ul> | ||
<a name=httpd></a> | <a name=httpd></a> | ||
<li><font color="#009000"><strong>004: RELIABILITY FIX: October 29, 2003</strong></font><br> | <li><font color="#009000"><strong>004: RELIABILITY FIX: November 1, 2003</strong></font><br> | ||
A user with write permission to <tt>httpd.conf</tt> or a <tt>.htaccess</tt> | A user with write permission to <tt>httpd.conf</tt> or a <tt>.htaccess</tt> | ||
file can crash | file can crash | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&sektion=8">httpd(8)</a> | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&sektion=8">httpd(8)</a> | ||
|
|
||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/004_httpd.patch">A source code patch exists which remedies the problem</a>.<br> | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/004_httpd.patch">A source code patch exists which remedies the problem</a>.<br> | ||
<p> | <p> | ||
<a name=arp></a> | <a name=arp></a> | ||
<li><font color="#009000"><strong>003: RELIABILITY FIX: October 1, 2003</strong></font><br> | <li><font color="#009000"><strong>003: RELIABILITY FIX: November 1, 2003</strong></font><br> | ||
It is possible for a local user to cause a system panic by flooding it with spoofed ARP | It is possible for a local user to cause a system panic by flooding it with spoofed ARP | ||
requests.<br> | requests.<br> | ||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/003_arp.patch">A source code patch exists which remedies the problem</a>.<br> | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/003_arp.patch">A source code patch exists which remedies the problem</a>.<br> | ||
<p> | <p> | ||
<a name=asn1></a> | <a name=asn1></a> | ||
<li><font color="#009000"><strong>002: SECURITY FIX: October 1, 2003</strong></font><br> | <li><font color="#009000"><strong>002: SECURITY FIX: November 1, 2003</strong></font><br> | ||
The use of certain ASN.1 encodings or malformed public keys may allow an | The use of certain ASN.1 encodings or malformed public keys may allow an | ||
attacker to mount a denial of service attack against applications linked with | attacker to mount a denial of service attack against applications linked with | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=3">ssl(3)</a>. | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&sektion=3">ssl(3)</a>. |