[BACK]Return to errata46.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata46.html between version 1.9 and 1.10

version 1.9, 2010/03/12 14:51:33 version 1.10, 2010/03/31 17:05:43
Line 87 
Line 87 
 <a name="zaurus"></a>  <a name="zaurus"></a>
   
 <ul>  <ul>
 <li><a name="013_ftpd"></a>  <li><a name="008_kerberos"></a>
   <font color="#009000"><strong>008: RELIABILITY FIX: March 31, 2010</strong></font> &nbsp; <i>All architectures</i><br>
   When decrypting packets, the internal decryption functions were not
   paranoid enough in checking for underruns, which could potentially
   lead to crashes.
   <br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/008_kerberos.patch">
   A source code patch exists which remedies this problem</a>.<br>
   <p>
   
   <li><a name="007_ftpd"></a>
 <font color="#009000"><strong>007: RELIABILITY FIX: March 12, 2010</strong></font> &nbsp; <i>All architectures</i><br>  <font color="#009000"><strong>007: RELIABILITY FIX: March 12, 2010</strong></font> &nbsp; <i>All architectures</i><br>
 Due to a null pointer dereference, it would be possible to crash ftpd when  Due to a null pointer dereference, it would be possible to crash ftpd when
 handling glob(3)'ing requests. This is non-exploitable.  handling glob(3)'ing requests. This is non-exploitable.

Legend:
Removed from v.1.9  
changed lines
  Added in v.1.10