Return to errata.html CVS log | Up to [local] / www |
version 1.464, 2003/11/10 04:36:49 | version 1.465, 2003/11/18 13:50:35 | ||
---|---|---|---|
|
|
||
<a name=i386></a> | <a name=i386></a> | ||
<li><h3><font color="#e00000">i386</font></h3> | <li><h3><font color="#e00000">i386</font></h3> | ||
<ul> | <ul> | ||
<li>No problems identified yet. | <a name=ibcs2></a> | ||
<li><font color="#009000"><strong>006: SECURITY FIX: November 17, 2003</strong></font><br> | |||
It may be possible for a local user to overrun the stack in | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=compat_ibcs2&sektion=8&apropos=0&manpath=OpenBSD+Current&arch=i386">compat_ibcs2(8)</a>.<br> | |||
ProPolice catches this, turning a potential privilege escalation into a denial | |||
of service. iBCS2 emulation does not need to be enabled via | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sysctl&sektion=8&apropos=0&manpath=OpenBSD+Current&arch=i386">sysctl(8)</a> | |||
for this to happen. | |||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/i386/006_ibcs2.patch"> | |||
A source code patch exists which remedies the problem</a>.<br> | |||
<p> | |||
</ul> | </ul> | ||
<p> | <p> | ||
<a name=alpha></a> | <a name=alpha></a> |