[BACK]Return to errata34.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata34.html between version 1.21 and 1.22

version 1.21, 2004/08/30 01:15:43 version 1.22, 2004/09/10 18:30:45
Line 56 
Line 56 
 <a name="all"></a>  <a name="all"></a>
 <h3><font color="#e00000">All architectures</font></h3>  <h3><font color="#e00000">All architectures</font></h3>
 <ul>  <ul>
   <li><a name="httpd4"></a>
   <font color="#009000"><strong>029: SECURITY FIX: September 10, 2004</strong></font><br>
   <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&amp;apropos=0&amp;sektion=8&amp;manpath=OpenBSD+Current&amp;arch=i386&amp;format=html">httpd(8)</a>
   's mod_rewrite module can be made to write one zero byte in an arbitrary memory
   position outside of a char array, causing a DoS or possibly buffer overflows.
   This would require enabling dbm for mod_rewrite and making use of a malicious
   dbm file.
   <br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/029_httpd4.patch">
   A source code patch exists which remedies this problem</a>.<br>
   <p>
   
 <li><a name="bridge"></a>  <li><a name="bridge"></a>
 <font color="#009000"><strong>028: RELIABILITY FIX: August 26, 2004</strong></font><br>  <font color="#009000"><strong>028: RELIABILITY FIX: August 26, 2004</strong></font><br>
 As  As

Legend:
Removed from v.1.21  
changed lines
  Added in v.1.22