version 1.8, 2003/11/21 16:55:16 |
version 1.9, 2004/01/16 00:53:26 |
|
|
<a name="all"></a> |
<a name="all"></a> |
<h3><font color="#e00000">All architectures</font></h3> |
<h3><font color="#e00000">All architectures</font></h3> |
<ul> |
<ul> |
|
<a name="isakmpd"></a> |
|
<li><font color="#009000"><strong>014: SECURITY FIX: January 15, 2004</strong></font><br> |
|
Several message handling flaws in |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=isakmpd&apropos=0&sektion=8&manpath=OpenBSD+Current&arch=i386&format=html">isakmpd(8)</a> |
|
have been reported by Thomas Walpuski. These allow an attacker to delete arbitrary SAs. The patch also |
|
includes a reliability fix for a filedescriptor leak that causes problems when a crypto card is |
|
installed. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.3/common/014_isakmpd.patch"> |
|
A source code patch exists which remedies these problems</a>.<br> |
|
<p> |
<li><a name="sem"></a> |
<li><a name="sem"></a> |
<font color="#009000"><strong>013: RELIABILITY FIX: November 20, 2003</strong></font><br> |
<font color="#009000"><strong>013: RELIABILITY FIX: November 20, 2003</strong></font><br> |
An improper bounds check makes it possible for a local user to cause a crash |
An improper bounds check makes it possible for a local user to cause a crash |