Return to errata34.html CVS log | Up to [local] / www |
version 1.22, 2004/09/10 18:30:45 | version 1.23, 2004/09/16 23:09:48 | ||
---|---|---|---|
|
|
||
<a name="all"></a> | <a name="all"></a> | ||
<h3><font color="#e00000">All architectures</font></h3> | <h3><font color="#e00000">All architectures</font></h3> | ||
<ul> | <ul> | ||
<li><a name="xpm"></a> | |||
<font color="#009000"><strong>030: SECURITY FIX: September 16, 2004</strong></font><br> | |||
Chris Evans reported several flaws (stack and integer overflows) in the | |||
<a href="http://www.inria.fr/koala/lehors/xpm.html">Xpm</a> | |||
library code that parses image files | |||
(<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0687">CAN-2004-0687</a>, | |||
<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0688">CAN-2004-0688</a>). | |||
Some of these would be exploitable when parsing malicious image files in | |||
an application that handles XPM images, if they could escape ProPolice. | |||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/030_xpm.patch"> | |||
A source code patch exists which remedies this problem</a>.<br> | |||
<p> | |||
<li><a name="httpd4"></a> | <li><a name="httpd4"></a> | ||
<font color="#009000"><strong>029: SECURITY FIX: September 10, 2004</strong></font><br> | <font color="#009000"><strong>029: SECURITY FIX: September 10, 2004</strong></font><br> | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&apropos=0&sektion=8&manpath=OpenBSD+Current&arch=i386&format=html">httpd(8)</a> | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&apropos=0&sektion=8&manpath=OpenBSD+Current&arch=i386&format=html">httpd(8)</a> |