version 1.1, 2003/10/24 22:12:40 |
version 1.2, 2003/10/30 23:02:35 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color="#e00000">All architectures</font></h3> |
<li><h3><font color="#e00000">All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=httpd></a> |
|
<li><font color="#009000"><strong>009: RELIABILITY FIX: October 29, 2003</strong></font><br> |
|
A user with write permission to <tt>httpd.conf</tt> or a <tt>.htaccess</tt> |
|
file can crash |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&sektion=8">httpd(8)</a> |
|
or potentially run arbitrary code as the user <tt>www</tt> (although it |
|
is believed that ProPolice will prevent code execution). |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.3/common/009_httpd.patch">A source code patch exists which remedies the problem</a>.<br> |
|
<p> |
<a name=arp></a> |
<a name=arp></a> |
<li><font color="#009000"><strong>008: RELIABILITY FIX: October 1, 2003</strong></font><br> |
<li><font color="#009000"><strong>008: RELIABILITY FIX: October 1, 2003</strong></font><br> |
It is possible for a local user to cause a system panic by flooding it with spoofed ARP |
It is possible for a local user to cause a system panic by flooding it with spoofed ARP |