version 1.13, 2009/01/09 13:13:58 |
version 1.14, 2009/01/14 22:38:11 |
|
|
|
|
<ul> |
<ul> |
|
|
|
<li><a name="008_bind"></a> |
|
<font color="#009000"><strong>008: SECURITY FIX: January 14, 2009</strong></font> <i>All architectures</i><br> |
|
named(8) did not correctly check the return value of a DSA verification |
|
function, potentially allowing bypass of verification of DNSSEC DSA |
|
signatures. |
|
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025">CVE-2009-0025</a>. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/008_bind.patch"> |
|
A source code patch exists which remedies this problem</a>.<br> |
|
<p> |
|
|
<li><a name="007_openssl"></a> |
<li><a name="007_openssl"></a> |
<font color="#009000"><strong>007: SECURITY FIX: January 9, 2009</strong></font> <i>All architectures</i><br> |
<font color="#009000"><strong>007: SECURITY FIX: January 9, 2009</strong></font> <i>All architectures</i><br> |
The OpenSSL libraries did not correctly check the return value from |
The OpenSSL libraries did not correctly check the return value from |