[BACK]Return to errata45.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata45.html between version 1.7 and 1.8

version 1.7, 2009/04/27 21:07:46 version 1.8, 2009/07/02 21:55:17
Line 85 
Line 85 
 <a name="zaurus"></a>  <a name="zaurus"></a>
   
 <ul>  <ul>
   <li><a name="006_perl"></a>
   <font color="#009000"><strong>006: RELIABILITY FIX: June 24, 2009</strong></font> &nbsp; <i>All architectures</i><br>
   An off-by-one error in the inflate function in Zlib.xs in the
   Compress::Raw::Zlib perl module before 2.017 (<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1391">CVE-2009-1391</a>),
   as used in AMaViS, SpamAssassin, and possibly other products,
   allows context-dependent attackers to cause a denial of service
   (hang or crash) via a crafted zlib compressed stream that
   triggers a heap-based buffer overflow.
   <br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/006_perl_zlib.patch">
   A source code patch exists which remedies this problem</a>.<br>
   <p>
   
   
 <li><a name="005_audio"></a>  <li><a name="005_audio"></a>
 <font color="#009000"><strong>005: RELIABILITY FIX: April 24, 2009</strong></font> &nbsp; <i>All architectures</i><br>  <font color="#009000"><strong>005: RELIABILITY FIX: April 24, 2009</strong></font> &nbsp; <i>All architectures</i><br>

Legend:
Removed from v.1.7  
changed lines
  Added in v.1.8