===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata30.html,v
retrieving revision 1.76
retrieving revision 1.77
diff -c -r1.76 -r1.77
*** www/errata30.html 2014/03/31 04:11:40 1.76
--- www/errata30.html 2014/03/31 16:02:48 1.77
***************
*** 78,84 ****
-
! 036: SECURITY FIX: November 14, 2002 All architectures
A buffer overflow in
named(8)
could allow an attacker to execute code with the privileges of named.
--- 78,85 ----
-
! 036: SECURITY FIX: November 14, 2002
! All architectures
A buffer overflow in
named(8)
could allow an attacker to execute code with the privileges of named.
***************
*** 88,94 ****
A source code patch exists which remedies this problem.
-
! 035: SECURITY FIX: November 6, 2002 All architectures
Incorrect argument checking in the
getrlimit(2)
system call may allow an attacker to crash the kernel.
--- 89,96 ----
A source code patch exists which remedies this problem.
-
! 035: SECURITY FIX: November 6, 2002
! All architectures
Incorrect argument checking in the
getrlimit(2)
system call may allow an attacker to crash the kernel.
***************
*** 96,102 ****
A source code patch exists which remedies this problem.
-
! 034: SECURITY FIX: November 6, 2002 All architectures
An attacker can bypass the restrictions imposed by sendmail's restricted shell,
smrsh(8),
and execute arbitrary commands with the privileges of his own account.
--- 98,105 ----
A source code patch exists which remedies this problem.
-
! 034: SECURITY FIX: November 6, 2002
! All architectures
An attacker can bypass the restrictions imposed by sendmail's restricted shell,
smrsh(8),
and execute arbitrary commands with the privileges of his own account.
***************
*** 104,110 ****
A source code patch exists which remedies this problem.
-
! 033: SECURITY FIX: October 21, 2002 All architectures
A buffer overflow can occur in the
kadmind(8)
daemon, leading to possible remote crash or exploit.
--- 107,114 ----
A source code patch exists which remedies this problem.
-
! 033: SECURITY FIX: October 21, 2002
! All architectures
A buffer overflow can occur in the
kadmind(8)
daemon, leading to possible remote crash or exploit.
***************
*** 112,125 ****
A source code patch exists which remedies this problem.
-
! 032: SECURITY FIX: October 7, 2002 All architectures
Incorrect argument checking in the
setitimer(2) system call may allow an attacker to write to kernel memory.
A source code patch exists which remedies this problem.
-
! 031: SECURITY FIX: August 11, 2002 All architectures
An insufficient boundary check in the
select(2)
system call allows an attacker to overwrite kernel memory and execute arbitrary
--- 116,131 ----
A source code patch exists which remedies this problem.
-
! 032: SECURITY FIX: October 7, 2002
! All architectures
Incorrect argument checking in the
setitimer(2) system call may allow an attacker to write to kernel memory.
A source code patch exists which remedies this problem.
-
! 031: SECURITY FIX: August 11, 2002
! All architectures
An insufficient boundary check in the
select(2)
system call allows an attacker to overwrite kernel memory and execute arbitrary
***************
*** 128,134 ****
A source code patch exists which remedies this problem.
-
! 030: SECURITY FIX: July 30, 2002 All architectures
Several remote buffer overflows can occur in the SSL2 server and SSL3 client of the
ssl(8)
library, as in the ASN.1 parser code in the
--- 134,141 ----
A source code patch exists which remedies this problem.
-
! 030: SECURITY FIX: July 30, 2002
! All architectures
Several remote buffer overflows can occur in the SSL2 server and SSL3 client of the
ssl(8)
library, as in the ASN.1 parser code in the
***************
*** 140,146 ****
This is the second version of the patch.
-
! 029: SECURITY FIX: July 29, 2002 All architectures
A buffer overflow can occur in the
xdr_array(3)
RPC code, leading to possible remote crash.
--- 147,154 ----
This is the second version of the patch.
-
! 029: SECURITY FIX: July 29, 2002
! All architectures
A buffer overflow can occur in the
xdr_array(3)
RPC code, leading to possible remote crash.
***************
*** 150,156 ****
This is the second version of the patch.
-
! 028: SECURITY FIX: July 29, 2002 All architectures
A race condition exists in the
pppd(8)
daemon which may cause it to alter the file permissions of an arbitrary file.
--- 158,165 ----
This is the second version of the patch.
-
! 028: SECURITY FIX: July 29, 2002
! All architectures
A race condition exists in the
pppd(8)
daemon which may cause it to alter the file permissions of an arbitrary file.
***************
*** 158,164 ****
A source code patch exists which remedies this problem.
-
! 027: RELIABILITY FIX: July 5, 2002 All architectures
Receiving IKE payloads out of sequence can cause
isakmpd(8) to crash.
--- 167,174 ----
A source code patch exists which remedies this problem.
-
! 027: RELIABILITY FIX: July 5, 2002
! All architectures
Receiving IKE payloads out of sequence can cause
isakmpd(8) to crash.
***************
*** 167,185 ****
This is the second version of the patch.
-
! 026: SECURITY FIX: June 27, 2002 All architectures
The kernel would let any user ktrace(2) set[ug]id processes.
A source code patch exists which remedies this problem.
-
! 025: SECURITY FIX: June 25, 2002 All architectures
A potential buffer overflow in the DNS resolver has been found.
A source code patch exists which remedies this problem.
-
! 024: SECURITY FIX: June 24, 2002 All architectures
All versions of OpenSSH's sshd between 2.3.1 and 3.3 contain an input validation
error that can result in an integer overflow and privilege escalation.
This problem is fixed in OpenSSH
--- 177,198 ----
This is the second version of the patch.
-
! 026: SECURITY FIX: June 27, 2002
! All architectures
The kernel would let any user ktrace(2) set[ug]id processes.
A source code patch exists which remedies this problem.
-
! 025: SECURITY FIX: June 25, 2002
! All architectures
A potential buffer overflow in the DNS resolver has been found.
A source code patch exists which remedies this problem.
-
! 024: SECURITY FIX: June 24, 2002
! All architectures
All versions of OpenSSH's sshd between 2.3.1 and 3.3 contain an input validation
error that can result in an integer overflow and privilege escalation.
This problem is fixed in OpenSSH
***************
*** 187,207 ****
security advisory.
-
! 023: SECURITY FIX: June 24, 2002 All architectures
A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd
module, leading to possible remote crash or exploit.
A source code patch exists which remedies this problem.
-
! 022: SECURITY FIX: June 19, 2002 All architectures
A buffer overflow can occur during the interpretation of chunked
encoding in the http daemon, leading to possible remote crash or exploit.
A source code patch exists which remedies this problem.
-
! 021: SECURITY FIX: May 8, 2002 All architectures
A race condition exists where an attacker could fill the file descriptor
table and defeat the kernel's protection of fd slots 0, 1, and 2 for a
setuid or setgid process.
--- 200,223 ----
security advisory.
-
! 023: SECURITY FIX: June 24, 2002
! All architectures
A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd
module, leading to possible remote crash or exploit.
A source code patch exists which remedies this problem.
-
! 022: SECURITY FIX: June 19, 2002
! All architectures
A buffer overflow can occur during the interpretation of chunked
encoding in the http daemon, leading to possible remote crash or exploit.
A source code patch exists which remedies this problem.
-
! 021: SECURITY FIX: May 8, 2002
! All architectures
A race condition exists where an attacker could fill the file descriptor
table and defeat the kernel's protection of fd slots 0, 1, and 2 for a
setuid or setgid process.
***************
*** 209,221 ****
A source code patch exists which remedies this problem.
-
! 020: SECURITY FIX: April 25, 2002 All architectures
A bug in sudo(8) may allow an attacker to corrupt the heap by specifying a custom prompt.
A source code patch exists which remedies this problem.
-
! 019: SECURITY FIX: April 22, 2002 All architectures
A local user can gain super-user privileges due to a buffer overflow
in sshd(8)
if AFS has been configured on the system or if
--- 225,239 ----
A source code patch exists which remedies this problem.
-
! 020: SECURITY FIX: April 25, 2002
! All architectures
A bug in sudo(8) may allow an attacker to corrupt the heap by specifying a custom prompt.
A source code patch exists which remedies this problem.
-
! 019: SECURITY FIX: April 22, 2002
! All architectures
A local user can gain super-user privileges due to a buffer overflow
in sshd(8)
if AFS has been configured on the system or if
***************
*** 226,232 ****
A source code patch exists which remedies this problem.
-
! 018: SECURITY FIX: April 11, 2002 All architectures
mail(1)
will process tilde escapes even in non-interactive mode.
This can lead to a local root compromise.
--- 244,251 ----
A source code patch exists which remedies this problem.
-
! 018: SECURITY FIX: April 11, 2002
! All architectures
mail(1)
will process tilde escapes even in non-interactive mode.
This can lead to a local root compromise.
***************
*** 235,241 ****
A source code patch exists which remedies this problem.
-
! 017: RELIABILITY FIX: March 26, 2002 All architectures
isakmpd(8)
will crash when receiving a zero length IKE packet due to a too-late length check.
--- 254,261 ----
A source code patch exists which remedies this problem.
-
! 017: RELIABILITY FIX: March 26, 2002
! All architectures
isakmpd(8)
will crash when receiving a zero length IKE packet due to a too-late length check.
***************
*** 243,249 ****
A source code patch exists which remedies this problem.
-
! 016: SECURITY FIX: March 19, 2002 All architectures
Under certain conditions, on systems using YP with netgroups in the password
database, it is possible for the
rexecd(8)
--- 263,270 ----
A source code patch exists which remedies this problem.
-
! 016: SECURITY FIX: March 19, 2002
! All architectures
Under certain conditions, on systems using YP with netgroups in the password
database, it is possible for the
rexecd(8)
***************
*** 259,265 ****
A source code patch exists which remedies this problem.
-
! 015: RELIABILITY FIX: March 13, 2002 All architectures
Under some circumstances the zlib compression library can free dynamically
allocated memory twice. This is not a security issue on OpenBSD since the BSD
free(3)
--- 280,287 ----
A source code patch exists which remedies this problem.
-
! 015: RELIABILITY FIX: March 13, 2002
! All architectures
Under some circumstances the zlib compression library can free dynamically
allocated memory twice. This is not a security issue on OpenBSD since the BSD
free(3)
***************
*** 270,289 ****
A source code patch exists which remedies this problem.
-
! 014: SECURITY FIX: March 8, 2002 All architectures
A local user can gain super-user privileges due to an off-by-one check
in the channel forwarding code of OpenSSH.
A source code patch exists which remedies this problem.
-
! 013: RELIABILITY FIX: February 4, 2002 All architectures
The wrong filedescriptors are released when pipe(2) failed.
A source code patch exists which remedies this problem.
-
! 012: SECURITY FIX: January 21, 2002 All architectures
A race condition between the ptrace(2) and execve(2) system calls allows
an attacker to modify the memory contents of suid/sgid processes which
could lead to compromise of the super-user account.
--- 292,314 ----
A source code patch exists which remedies this problem.
-
! 014: SECURITY FIX: March 8, 2002
! All architectures
A local user can gain super-user privileges due to an off-by-one check
in the channel forwarding code of OpenSSH.
A source code patch exists which remedies this problem.
-
! 013: RELIABILITY FIX: February 4, 2002
! All architectures
The wrong filedescriptors are released when pipe(2) failed.
A source code patch exists which remedies this problem.
-
! 012: SECURITY FIX: January 21, 2002
! All architectures
A race condition between the ptrace(2) and execve(2) system calls allows
an attacker to modify the memory contents of suid/sgid processes which
could lead to compromise of the super-user account.
***************
*** 291,297 ****
A source code patch exists which remedies this problem.
-
! 011: SECURITY FIX: January 17, 2002 All architectures
If the Postfix sendmail replacement is installed on a system an
attacker may be able to gain root privileges on the local host via
sudo(8) which runs the mailer as root with an environment inherited
--- 316,323 ----
A source code patch exists which remedies this problem.
-
! 011: SECURITY FIX: January 17, 2002
! All architectures
If the Postfix sendmail replacement is installed on a system an
attacker may be able to gain root privileges on the local host via
sudo(8) which runs the mailer as root with an environment inherited
***************
*** 304,310 ****
A source code patch exists which remedies this problem.
-
! 010: RELIABILITY FIX: December 13, 2001 All architectures
Systems running with IP-in-IP encapsulation can be made to crash by
malformed packets.
--- 330,337 ----
A source code patch exists which remedies this problem.
-
! 010: RELIABILITY FIX: December 13, 2001
! All architectures
Systems running with IP-in-IP encapsulation can be made to crash by
malformed packets.
***************
*** 321,327 ****
boot cd:,OFWBOOT /3.0/macppc/bsd.rd
-
! 008: SECURITY FIX: November 28, 2001 All architectures
A security issue exists in the lpd daemon that may allow an attacker
to create arbitrary new files in the root directory. Only machines
with line printer access (ie: listed in either /etc/hosts.lpd or
--- 348,355 ----
boot cd:,OFWBOOT /3.0/macppc/bsd.rd
-
! 008: SECURITY FIX: November 28, 2001
! All architectures
A security issue exists in the lpd daemon that may allow an attacker
to create arbitrary new files in the root directory. Only machines
with line printer access (ie: listed in either /etc/hosts.lpd or
***************
*** 332,338 ****
A source code patch exists which remedies this problem.
-
! 007: SECURITY FIX: November 13, 2001 All architectures
A security issue exists in the vi.recover script that may allow an attacker
to remove arbitrary zero-length files, regardless of ownership.
--- 360,367 ----
A source code patch exists which remedies this problem.
-
! 007: SECURITY FIX: November 13, 2001
! All architectures
A security issue exists in the vi.recover script that may allow an attacker
to remove arbitrary zero-length files, regardless of ownership.
***************
*** 340,346 ****
A source code patch exists which remedies this problem.
-
! 006: SECURITY FIX: November 13, 2001 All architectures
pf(4)
was incapable of dealing with certain ipv6 icmp packets, resulting in a crash.
--- 369,376 ----
A source code patch exists which remedies this problem.
-
! 006: SECURITY FIX: November 13, 2001
! All architectures
pf(4)
was incapable of dealing with certain ipv6 icmp packets, resulting in a crash.
***************
*** 374,380 ****
A source code patch exists which remedies this problem.
-
! 002: SECURITY FIX: November 12, 2001 All architectures
sshd(8)
is being upgraded from OpenSSH 3.0 to OpenSSH 3.0.2 to fix a few problems:
--- 404,411 ----
A source code patch exists which remedies this problem.
-
! 002: SECURITY FIX: November 12, 2001
! All architectures
sshd(8)
is being upgraded from OpenSSH 3.0 to OpenSSH 3.0.2 to fix a few problems:
***************
*** 401,407 ****
This is the second version of this patch.
-
! 001: INSTALL ISSUE: November 12, 2001 All architectures
A small bug in the installation script causes the /etc/hosts file to
be incorrectly formed.
The resulting file contains a line which reads like:
--- 432,439 ----
This is the second version of this patch.
-
! 001: INSTALL ISSUE: November 12, 2001
! All architectures
A small bug in the installation script causes the /etc/hosts file to
be incorrectly formed.
The resulting file contains a line which reads like: