version 1.18, 2006/10/07 18:32:35 |
version 1.19, 2006/10/12 07:05:21 |
|
|
<a name="vax"></a> |
<a name="vax"></a> |
<ul> |
<ul> |
|
|
|
<li><a name="ssh2"></a> |
|
<font color="#009000"><strong>020: SECURITY FIX: October 12, 2006</strong></font> <i>All architectures</i><br> |
|
Fix 2 security bugs found in OpenSSH. A pre-authenication denial of service (found |
|
by Tavis Ormandy) that would cause |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sshd&sektion=8">sshd(8)</a> |
|
to spin until the login grace time expired. |
|
An unsafe signal handler (found by Mark Dowd) that is vulnerable to a race condition |
|
that could be exploited to perform a pre-authentication denial of service. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/020_ssh2.patch"> |
|
A source code patch exists which remedies this problem</a>.<br> |
|
<p> |
|
|
<li><a name="systrace"></a> |
<li><a name="systrace"></a> |
<font color="#009000"><strong>019: SECURITY FIX: October 7, 2006</strong></font> <i>All architectures</i><br> |
<font color="#009000"><strong>019: SECURITY FIX: October 7, 2006</strong></font> <i>All architectures</i><br> |
Fix for an integer overflow in |
Fix for an integer overflow in |