Return to errata34.html CVS log | Up to [local] / www |
version 1.13, 2004/06/09 19:33:24 | version 1.14, 2004/06/11 03:48:57 | ||
---|---|---|---|
|
|
||
<a name="all"></a> | <a name="all"></a> | ||
<h3><font color="#e00000">All architectures</font></h3> | <h3><font color="#e00000">All architectures</font></h3> | ||
<ul> | <ul> | ||
<li><a name="isakmpd3"></a> | |||
<font color="#009000"><strong>024: SECURITY FIX: Jun 10, 2004</strong></font><br> | |||
As | |||
<a href="http://seclists.org/lists/fulldisclosure/2004/Jun/0191.html">disclosed</a> | |||
by Thomas Walpuski | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=isakmpd&apropos=0&sektion=8&manpath=OpenBSD+Current&arch=i386&format=html">isakmpd(8)</a> | |||
is still vulnerable to unauthorized SA deletion. An attacker can delete IPsec | |||
tunnels at will. | |||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/024_isakmpd3.patch"> | |||
A source code patch exists which remedies this problem</a>.<br> | |||
<p> | |||
<li><a name="cvs3"></a> | <li><a name="cvs3"></a> | ||
<font color="#009000"><strong>023: SECURITY FIX: Jun 9, 2004</strong></font><br> | <font color="#009000"><strong>023: SECURITY FIX: Jun 9, 2004</strong></font><br> | ||
Multiple remote vulnerabilities have been found in the | Multiple remote vulnerabilities have been found in the |