Return to errata48.html CVS log | Up to [local] / www |
version 1.4, 2010/11/18 08:34:45 | version 1.5, 2010/12/17 16:36:18 | ||
---|---|---|---|
|
|
||
<a name="zaurus"></a> | <a name="zaurus"></a> | ||
<ul> | <ul> | ||
<li><a name="006_cbc"></a> | |||
<font color="#009000"><strong>006: RELIABILITY FIX: December 17, 2010</strong></font> <i>All architectures</i><br> | |||
Bring CBC oracle attack countermeasures to hardware crypto accelerator land. | |||
This fixes aes-ni, via xcrypt and various drivers | |||
(<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=glxsb&arch=i386&sektion=4">glxsb(4)</a>, | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=hifn&sektion=4">hifn(4)</a>, | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=safe&sektion=4">safe(4)</a> | |||
and | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ubsec&sektion=4">ubsec(4)</a>). | |||
<br> | |||
<a href="http://ftp.openbsd.org/pub/OpenBSD/patches/4.8/common/006_cbc.patch"> | |||
A source code patch exists which remedies this problem</a>.<br> | |||
<p> | |||
<li><a name="005_pf"></a> | |||
<font color="#009000"><strong>005: SECURITY FIX: December 17, 2010</strong></font> <i>All architectures</i><br> | |||
Insufficent initialization of the pf rule structure in the ioctl | |||
handler may allow userland to modify kernel memory. By default root | |||
privileges are needed to add or modify pf rules. | |||
<br> | |||
<a href="http://ftp.openbsd.org/pub/OpenBSD/patches/4.8/common/005_pf.patch"> | |||
A source code patch exists which remedies this problem</a>.<br> | |||
<p> | |||
<li><a name="004_openssl"></a> | <li><a name="004_openssl"></a> | ||
<font color="#009000"><strong>004: RELIABILITY FIX: November 17, 2010</strong></font> <i>All architectures</i><br> | <font color="#009000"><strong>004: RELIABILITY FIX: November 17, 2010</strong></font> <i>All architectures</i><br> | ||
Fix a flaw in the OpenSSL TLS server extension code parsing which could lead to | Fix a flaw in the OpenSSL TLS server extension code parsing which could lead to |