[BACK]Return to errata66.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata66.html between version 1.6 and 1.7

version 1.6, 2019/11/21 21:01:42 version 1.7, 2019/12/04 11:11:35
Line 179 
Line 179 
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
   
   <li id="p009_mesaxlock">
   <strong>009: SECURITY FIX: December 4, 2019</strong>
   &nbsp; <i>All architectures</i>
   <br>
   Environment-provided paths are used for dlopen() in mesa, resulting in
   escalation to the auth group in xlock(1).
   <br>
   <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/6.6/common/009_mesaxlock.patch.sig">
   A source code patch exists which remedies this problem.</a>
   <p>
   
   <li id="p010_libcauth">
   <strong>010: SECURITY FIX: December 4, 2019</strong>
   &nbsp; <i>All architectures</i>
   <br>
   libc's authentication layer performed insufficient username validation.
   <br>
   <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/6.6/common/010_libcauth.patch.sig">
   A source code patch exists which remedies this problem.</a>
   <p>
   
   <li id="p011_xenodm">
   <strong>011: SECURITY FIX: December 4, 2019</strong>
   &nbsp; <i>All architectures</i>
   <br>
   xenodm uses the libc authentication layer incorrectly.
   <br>
   <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/6.6/common/011_xenodm.patch.sig">
   A source code patch exists which remedies this problem.</a>
   <p>
   
 </ul>  </ul>
   
 <hr>  <HR>

Legend:
Removed from v.1.6  
changed lines
  Added in v.1.7