=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata28.html,v retrieving revision 1.29 retrieving revision 1.30 diff -u -r1.29 -r1.30 --- www/errata28.html 2002/10/17 21:38:38 1.29 +++ www/errata28.html 2003/03/06 21:44:07 1.30 @@ -1,8 +1,8 @@ - + OpenBSD 2.8 errata - + @@ -13,7 +13,7 @@ [OpenBSD] -

+

This is the OpenBSD 2.8 release errata & patch list:

@@ -36,7 +36,7 @@

- + You can also fetch a tar.gz file containing all the following patches. This file is updated once a day. @@ -50,11 +50,11 @@
-
  • All architectures

    +
  • All architectures

    -

  • 013: SECURITY FIX: Dec 18, 2000
    -Procfs contained numerous overflows, which could lead an intruder to root permissions. Procfs is NOT enabled by default in OpenBSD.
    +
  • 013: SECURITY FIX: Dec 18, 2000
    +Procfs contained numerous overflows, which could lead an intruder to root permissions. Procfs is NOT enabled by default in OpenBSD.
    A source code patch exists which remedies the problem.

    -

  • 011: RELIABILITY FIX: Dec 13, 2000
    +
  • 011: RELIABILITY FIX: Dec 13, 2000
    The crypto subsystem could incorrectly fail to run certain software ciphers, if a hardware card existed in the machine.
    A source code patch exists which remedies the problem.

    -

  • 010: RELIABILITY FIX: Dec 11, 2000
    +
  • 010: RELIABILITY FIX: Dec 11, 2000
    A crash could occur during fast routing, if IPSEC was enabled.
    A source code patch exists which remedies the problem.

    -

  • 009: SECURITY FIX: Dec 10, 2000
    +
  • 009: SECURITY FIX: Dec 10, 2000
    Another problem exists in the Kerberos libraries.
    A source code patch exists which remedies the problem.

    -

  • 008: SECURITY FIX: Dec 7, 2000
    +
  • 008: SECURITY FIX: Dec 7, 2000
    Two problems have recently been discovered in the KerberosIV code.

    1. A symlink problem was discovered in the KerberosIV password checking routines /usr/bin/su and /usr/bin/login, which makes it possible for a @@ -232,42 +232,42 @@ A source code patch exists which remedies the problem.

    -

  • 005: SECURITY FIX: Dec 4, 2000
    +
  • 005: SECURITY FIX: Dec 4, 2000
    OpenBSD 2.8's ftpd contains a one-byte overflow in the replydirname() function.
    A source code patch exists which remedies the problem.
    You can view the OpenBSD Advisory here.

    -

  • 004: RELIABILITY FIX: Nov 17, 2000
    +
  • 004: RELIABILITY FIX: Nov 17, 2000
    First off, AES (Rijndael) encryption and decryption were broken for IPsec and swap encryption.
    Secondly, the AES code did not work properly on big endian machines.
    A second revision source code patch exists which remedies the problem.

    -

  • 002: IMPLEMENTATION FIX: Nov 10, 2000
    +
  • 002: IMPLEMENTATION FIX: Nov 10, 2000
    In ssh(1), skey support for SSH1 protocol was broken. Some people might consider that kind of important.
    - + A source code patch exists which remedies this problem.

    -

  • i386

    +
  • i386

      -
    • 022: SECURITY FIX: Mar 2, 2001
      +
    • 022: SECURITY FIX: Mar 2, 2001
      The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory. This option is not on by default. A source code patch exists which remedies the problem.

      -

    • 015: STABILITY FIX: Dec 22, 2000
      +
    • 015: STABILITY FIX: Dec 22, 2000
      Some machines locked up while trying to use the mouse in console mode. This patch solves that problem.
      A source code patch exists which remedies this problem.

      -

    • 006: STABILITY FIX: Dec 4, 2000
      +
    • 006: STABILITY FIX: Dec 4, 2000
      On some machines, a PCIBIOS device driver interrupt allocation bug can cause a kernel hang while probing PCI devices. If you have this symptom, you can disable PCIBIOS as a workaround. To do this, @@ -286,10 +286,10 @@

    -

  • mac68k

    +
  • mac68k

      -
    • 007: INSTALL PROBLEM: Dec 4, 2000
      +
    • 007: INSTALL PROBLEM: Dec 4, 2000
      The X packages share28.tgz and @@ -303,10 +303,10 @@

    -

  • sparc

    +
  • sparc

    -

  • amiga

    +
  • amiga

      -
    • 007: INSTALL PROBLEM: Dec 4, 2000
      +
    • 007: INSTALL PROBLEM: Dec 4, 2000
      The X packages share28.tgz and @@ -350,16 +350,16 @@

    -

  • pmax

    +
  • pmax

    • No problems identified yet.

    -

  • hp300

    +
  • hp300

      -
    • 007: INSTALL PROBLEM: Dec 4, 2000
      +
    • 007: INSTALL PROBLEM: Dec 4, 2000
      The X packages share28.tgz and @@ -373,10 +373,10 @@

    -

  • mvme68k

    +
  • mvme68k

      -
    • 007: INSTALL PROBLEM: Dec 4, 2000
      +
    • 007: INSTALL PROBLEM: Dec 4, 2000
      The X packages share28.tgz and @@ -390,10 +390,10 @@

    -

  • powerpc

    +
  • powerpc

      -
    • 012: INSTALL PROBLEM: Dec 14, 2000
      +
    • 012: INSTALL PROBLEM: Dec 14, 2000
      The IMac DV+ (and probably some other machines) incorrectly identify their video hardware, but it is possible to work around the problem.
      @@ -401,16 +401,16 @@

    -

  • vax

    +
  • vax

    • No problems identified yet.

    -

  • sun3

    +
  • sun3

      -
    • 007: INSTALL PROBLEM: Dec 4, 2000
      +
    • 007: INSTALL PROBLEM: Dec 4, 2000
      The X packages share28.tgz and @@ -445,8 +445,8 @@
      OpenBSD -www@openbsd.org -
      $OpenBSD: errata28.html,v 1.29 2002/10/17 21:38:38 deraadt Exp $ +www@openbsd.org +
      $OpenBSD: errata28.html,v 1.30 2003/03/06 21:44:07 naddy Exp $