[BACK]Return to errata26.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata26.html between version 1.75 and 1.76

version 1.75, 2016/08/15 02:22:06 version 1.76, 2016/10/16 19:11:29
Line 70 
Line 70 
 <br>  <br>
 <hr>  <hr>
   
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6.tar.gz">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6.tar.gz">
 You can also fetch a tar.gz file containing all the following patches</a>.  You can also fetch a tar.gz file containing all the following patches</a>.
 This file is updated once a day.  This file is updated once a day.
 <p>  <p>
Line 94 
Line 94 
 used as a local denial of service attack which would block the exiting of  used as a local denial of service attack which would block the exiting of
 processes which had semaphore resources allocated. Processes not using  processes which had semaphore resources allocated. Processes not using
 semaphores are not affected, so the actual effect is very minimal.<br>  semaphores are not affected, so the actual effect is very minimal.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/024_sysv_sem.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/024_sysv_sem.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="ipf">  <li id="ipf">
Line 105 
Line 105 
 bypassed.  bypassed.
 This patch also includes fixes for an unaligned timestamp issue,  This patch also includes fixes for an unaligned timestamp issue,
 and reliability fixes for ipmon and the in-kernel ftp proxy.<br>  and reliability fixes for ipmon and the in-kernel ftp proxy.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/023_ipf.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/023_ipf.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 It updates ipf to version 3.3.16.  It updates ipf to version 3.3.16.
 <p>  <p>
Line 121 
Line 121 
 the impact is much reduced.<br>  the impact is much reduced.<br>
 (Aside:  We do not consider this a localhost root hole in the default install,  (Aside:  We do not consider this a localhost root hole in the default install,
 since we have not seen a fast blowfish cracker yet ;-)<br>  since we have not seen a fast blowfish cracker yet ;-)<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/022_xlockmore.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/022_xlockmore.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 This is the 2nd patch designed to solve this problem.  This is the 2nd patch designed to solve this problem.
 <p>  <p>
Line 138 
Line 138 
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 syslog(3) would not try to reopen the socket, thus, nightly newsyslog(8)  syslog(3) would not try to reopen the socket, thus, nightly newsyslog(8)
 would cause syslogd(8) to not see new messages.  would cause syslogd(8) to not see new messages.
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/020_syslog.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/020_syslog.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="nsphy">  <li id="nsphy">
Line 146 
Line 146 
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 Intel fxp cards with National Semiconductor PHYs (nsphy) have trouble  Intel fxp cards with National Semiconductor PHYs (nsphy) have trouble
 negotiating and maintaining 100Mb link integrity.<br>  negotiating and maintaining 100Mb link integrity.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/019_nsphy.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/019_nsphy.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="procfs">  <li id="procfs">
Line 156 
Line 156 
 to having the stderr output of setuid processes directed onto  to having the stderr output of setuid processes directed onto
 a pre-seeked descriptor onto the stack in their own procfs memory.<br>  a pre-seeked descriptor onto the stack in their own procfs memory.<br>
 Note that procfs is not mounted by default in OpenBSD.<br>  Note that procfs is not mounted by default in OpenBSD.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/018_procfs.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/018_procfs.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="fortran">  <li id="fortran">
Line 164 
Line 164 
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 Fortran doesn't work right.  The file /usr/include/g2c.h is missing in the  Fortran doesn't work right.  The file /usr/include/g2c.h is missing in the
 release.<br>  release.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/008_fortran.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/008_fortran.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 The patch fixes the source tree and describes how to properly add  The patch fixes the source tree and describes how to properly add
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/g2c.h">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/g2c.h">
 the include file</a> to your system.  the include file</a> to your system.
 <p>  <p>
 <li id="sslUSA">  <li id="sslUSA">
Line 177 
Line 177 
 USA version of the libssl package (called <strong>sslUSA</strong>, is  USA version of the libssl package (called <strong>sslUSA</strong>, is
 possibly exploitable in isakmpd if SSL/RSA features  possibly exploitable in isakmpd if SSL/RSA features
 are enabled or used.<br>  are enabled or used.<br>
 <a href="http://www.openssh.com">OpenSSH</a> and httpd (with -DSSL) are not  <a href="https://www.openssh.com">OpenSSH</a> and httpd (with -DSSL) are not
 vulnerable.<br>  vulnerable.<br>
 <strong>NOTE: International users using the ssl26 package are not affected.</strong>  <strong>NOTE: International users using the ssl26 package are not affected.</strong>
 <p>  <p>
Line 203 
Line 203 
 <font color="#009000"><strong>015: Y2K FIX: Jan 9, 2000</strong></font>  <font color="#009000"><strong>015: Y2K FIX: Jan 9, 2000</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 The at(1) command was unable to parse some kinds of dates.<br>  The at(1) command was unable to parse some kinds of dates.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/015_aty2k.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/015_aty2k.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="eepromy2k">  <li id="eepromy2k">
 <font color="#009000"><strong>014: Y2K FIX: Jan 3, 2000</strong></font><br>  <font color="#009000"><strong>014: Y2K FIX: Jan 3, 2000</strong></font><br>
 A minor problem; the sparc eeprom(8) command is not Y2K compliant.<br>  A minor problem; the sparc eeprom(8) command is not Y2K compliant.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/sparc/014_eepromy2k.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/sparc/014_eepromy2k.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 This is the second revision of the patch.  This is the second revision of the patch.
 <p>  <p>
Line 217 
Line 217 
 <font color="#009000"><strong>013: Y2K FIX: Jan 3, 2000</strong></font>  <font color="#009000"><strong>013: Y2K FIX: Jan 3, 2000</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 A minor problem in the logging support for the adduser(8) command.<br>  A minor problem in the logging support for the adduser(8) command.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/013_addusery2k.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/013_addusery2k.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="3c900b">  <li id="3c900b">
Line 225 
Line 225 
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 The 3C900B-TPO fails to select the correct media type (it never sees or  The 3C900B-TPO fails to select the correct media type (it never sees or
 sends packets).<br>  sends packets).<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/012_3c900b.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/012_3c900b.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="poll">  <li id="poll">
 <font color="#009000"><strong>011: SECURITY FIX: Dec 4, 1999</strong></font>  <font color="#009000"><strong>011: SECURITY FIX: Dec 4, 1999</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 Various bugs in poll(2) may cause a kernel crash.<br>  Various bugs in poll(2) may cause a kernel crash.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/011_poll.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/011_poll.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="sendmail">  <li id="sendmail">
 <font color="#009000"><strong>010: SECURITY FIX: Dec 4, 1999</strong></font>  <font color="#009000"><strong>010: SECURITY FIX: Dec 4, 1999</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 Sendmail had a race in aliases file handling, which this patch fixes.<br>  Sendmail had a race in aliases file handling, which this patch fixes.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/010_sendmail.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/010_sendmail.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="atapijumbo">  <li id="atapijumbo">
Line 248 
Line 248 
 Various improvements have been made to the IDE/ATAPI subsystem since  Various improvements have been made to the IDE/ATAPI subsystem since
 the 2.6 release shipped.<br>  the 2.6 release shipped.<br>
 Some of these improvements make some recalcitrant devices work much better.  Some of these improvements make some recalcitrant devices work much better.
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/009_atapi.patch"><br>  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/009_atapi.patch"><br>
 Revision 1 of this jumbo source code patch exists.</a><br>  Revision 1 of this jumbo source code patch exists.</a><br>
 <p>  <p>
 <li id="hp300_locore">  <li id="hp300_locore">
 <font color="#009000"><strong>007: RELIABILITY FIX: Nov 12, 1999</strong></font>  <font color="#009000"><strong>007: RELIABILITY FIX: Nov 12, 1999</strong></font>
 &nbsp; <i>m68k architectures</i><br>  &nbsp; <i>m68k architectures</i><br>
 All m68k kernels can possibly be crashed by a user.<br>  All m68k kernels can possibly be crashed by a user.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/m68k/007_locore.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/m68k/007_locore.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="alpha_locore">  <li id="alpha_locore">
 <font color="#009000"><strong>006: RELIABILITY FIX: Nov 13, 1999</strong></font>  <font color="#009000"><strong>006: RELIABILITY FIX: Nov 13, 1999</strong></font>
 &nbsp; <i>alpha only</i><br>  &nbsp; <i>alpha only</i><br>
 The alpha kernel can possibly be crashed by a user.<br>  The alpha kernel can possibly be crashed by a user.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/alpha/006_locore.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/alpha/006_locore.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="sshjumbo">  <li id="sshjumbo">
Line 271 
Line 271 
 Various OpenSSH improvements have been made since the 2.6 release shipped.<br>  Various OpenSSH improvements have been made since the 2.6 release shipped.<br>
 To resolve the various (non-security related) features which users may want,  To resolve the various (non-security related) features which users may want,
 we are making a jumbo patch available.  <strong>This is now at VERSION FOUR.</strong><br>  we are making a jumbo patch available.  <strong>This is now at VERSION FOUR.</strong><br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/005_sshjumbo.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/005_sshjumbo.patch">
 Revision 4 of this jumbo source code patch exists.</a><br>  Revision 4 of this jumbo source code patch exists.</a><br>
 <strong>NOTE: /etc/sshd_config and /etc/ssh_config may need changes.</strong>  <strong>NOTE: /etc/sshd_config and /etc/ssh_config may need changes.</strong>
 <p>  <p>
Line 279 
Line 279 
 <font color="#009000"><strong>004: RELIABILITY FIX: Nov 12, 1999</strong></font>  <font color="#009000"><strong>004: RELIABILITY FIX: Nov 12, 1999</strong></font>
 &nbsp; <i>sparc only</i><br>  &nbsp; <i>sparc only</i><br>
 The sparc kernel can be crashed by a user.<br>  The sparc kernel can be crashed by a user.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/sparc/004_locore.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/sparc/004_locore.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="m4">  <li id="m4">
 <font color="#009000"><strong>003: FUNCTIONALITY FIX: Nov 10, 1999</strong></font>  <font color="#009000"><strong>003: FUNCTIONALITY FIX: Nov 10, 1999</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 m4 is quite broken in the 2.6 release.<br>  m4 is quite broken in the 2.6 release.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/003_m4.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/003_m4.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 This is the 3rd revision of the patch.  This is the 3rd revision of the patch.
 <p>  <p>
Line 294 
Line 294 
 <font color="#009000"><strong>002: SECURITY FIX: Nov 9, 1999</strong></font>  <font color="#009000"><strong>002: SECURITY FIX: Nov 9, 1999</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 Any user can change interface media configurations.<br>  Any user can change interface media configurations.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/002_ifmedia.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/002_ifmedia.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li id="newsyslog">  <li id="newsyslog">
 <font color="#009000"><strong>001: RELIABILITY FIX: Nov 8, 1999</strong></font>  <font color="#009000"><strong>001: RELIABILITY FIX: Nov 8, 1999</strong></font>
 &nbsp; <i>All architectures</i><br>  &nbsp; <i>All architectures</i><br>
 A race condition in newsyslog(8) can cause errors in log file rotation.<br>  A race condition in newsyslog(8) can cause errors in log file rotation.<br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/001_newsyslog.patch">  <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/001_newsyslog.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
   

Legend:
Removed from v.1.75  
changed lines
  Added in v.1.76