version 1.3, 2000/05/25 16:41:35 |
version 1.4, 2000/05/25 20:42:30 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=ipf></a> |
|
<li><font color=#009000><strong>023: SECURITY FIX: May 25, 2000</strong></font><br> |
|
A misuse of <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ipf&sektion=8">ipf(8)</a> |
|
<i>keep-state</i> rules can result in firewall rules being |
|
bypassed. This patch also includes fixes for an unaligned timestamp issue, |
|
and reliability fixes for ipmon and the in-kernel ftp proxy.<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/023_ipf.patch> |
|
A jumbo patch exists</a>, which remedies this problem, and updates ipf |
|
to version 3.3.16. |
|
<p> |
<a name=xlockmore></a> |
<a name=xlockmore></a> |
<li><font color=#009000><strong>022: SECURITY FIX: May 25, 2000</strong></font><br> |
<li><font color=#009000><strong>022: SECURITY FIX: May 25, 2000</strong></font><br> |
xlockmore has a localhost attack against it which allows recovery of the encrypted |
xlockmore has a localhost attack against it which allows recovery of the encrypted |