[BACK]Return to errata27.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata27.html between version 1.62 and 1.63

version 1.62, 2013/10/26 15:21:13 version 1.63, 2014/02/27 17:26:45
Line 56 
Line 56 
 <a href="errata51.html">5.1</a>,  <a href="errata51.html">5.1</a>,
 <a href="errata52.html">5.2</a>,  <a href="errata52.html">5.2</a>,
 <a href="errata53.html">5.3</a>,  <a href="errata53.html">5.3</a>,
 <a href="errata54.html">5.4</a>.  <a href="errata54.html">5.4</a>,
   <a href="errata55.html">5.5</a>.
 <br>  <br>
 <hr>  <hr>
   
Line 118 
Line 119 
 <font color="#009000"><strong>032: SECURITY FIX: Oct 26, 2000</strong></font><br>  <font color="#009000"><strong>032: SECURITY FIX: Oct 26, 2000</strong></font><br>
 There are two possibly exploitable potential buffer overflows in the X11  There are two possibly exploitable potential buffer overflows in the X11
 libraries using the xtrans code. One of these vulnerabilities was  libraries using the xtrans code. One of these vulnerabilities was
 reported to the  reported to the
 <a href="http://www.securityfocus.com/archive/1/139436">BUGTRAQ</a>  <a href="http://www.securityfocus.com/archive/1/139436">BUGTRAQ</a>
 mailing list.  mailing list.
 <br>  <br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/032_xtrans.patch">  <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/032_xtrans.patch">
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
 <li><a name="httpd"></a>  <li><a name="httpd"></a>
 <font color="#009000"><strong>031: SECURITY FIX: Oct 18, 2000</strong></font><br>  <font color="#009000"><strong>031: SECURITY FIX: Oct 18, 2000</strong></font><br>
 Apache has several bugs in <tt>mod_rewrite</tt> and <tt>mod_vhost_alias</tt>  Apache has several bugs in <tt>mod_rewrite</tt> and <tt>mod_vhost_alias</tt>
 that could cause arbitrary files accessible to the www user on the server  that could cause arbitrary files accessible to the www user on the server
 to be exposed under certain configurations when these modules are used.  to be exposed under certain configurations when these modules are used.
 (These modules are not active by default).  (These modules are not active by default).
 <br>  <br>
Line 234 
Line 235 
 <p>  <p>
 <li><a name="ftpd"></a>  <li><a name="ftpd"></a>
 <font color="#009000"><strong>019: SECURITY FIX: July 5, 2000</strong></font><br>  <font color="#009000"><strong>019: SECURITY FIX: July 5, 2000</strong></font><br>
 Just like pretty much all the other unix ftp daemons on the planet,  Just like pretty much all the other unix ftp daemons on the planet,
 ftpd had a remote root hole in it.  Luckily, ftpd was not enabled by default.  ftpd had a remote root hole in it.  Luckily, ftpd was not enabled by default.
 The problem exists if anonymous ftp is enabled.  The problem exists if anonymous ftp is enabled.
 <br>  <br>
Line 251 
Line 252 
 <li><a name="screen"></a>  <li><a name="screen"></a>
 <font color="#009000"><strong>017: INSTALLATION FIX: July 3, 2000</strong></font>  <font color="#009000"><strong>017: INSTALLATION FIX: July 3, 2000</strong></font>
 <br>  <br>
 The screen package shipped with 2.7 does not install itself properly.  The  The screen package shipped with 2.7 does not install itself properly.  The
 existing package in 2.7/packages/_ARCH_/screen-3.9.5.tgz has been renamed to  existing package in 2.7/packages/_ARCH_/screen-3.9.5.tgz has been renamed to
 screen-3.9.5.tgz.old and a replacement package has been provided under the  screen-3.9.5.tgz.old and a replacement package has been provided under the
 name screen-3.9.5p1.tgz.  name screen-3.9.5p1.tgz.
 <br>  <br>
 <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.7/ports/017_screen.patch">  <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/2.7/ports/017_screen.patch">
Line 512 
Line 513 
 <br>  <br>
   
 <hr>  <hr>
 <a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>  <a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
 <a href="mailto:www@openbsd.org">www@openbsd.org</a>  <a href="mailto:www@openbsd.org">www@openbsd.org</a>
 <br><small>$OpenBSD$</small>  <br><small>$OpenBSD$</small>
   

Legend:
Removed from v.1.62  
changed lines
  Added in v.1.63