<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
  <channel>
    <title>OpenBSD 40 Errata</title>
    <link>http://www.openbsd.org/errata40.html</link>
    <description>OpenBSD 40 Errata</description>
    <language>en-us</language>
    <managingEditor>mike@erdelynet.com</managingEditor>

    <image>
      <title>erdelynet.com</title>
      <url>http://erdelynet.com/images/puffy96x83.gif</url>
      <link>http://www.openbsd.org/errata40.html</link>
      <width>96</width>
      <height>83</height>
      <description>OpenBSD 40 Errata</description>
    </image>

    <item>
      <title>017 SECURITY 017_openssl</title>
      <link>http://www.openbsd.org/errata40.html#017_openssl</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>October 10, 2007</pubDate>
      <description><![CDATA[
 The SSL_get_shared_ciphers() function in OpenSSL contains an off-by-one overflow. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/017_openssl.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>016 SECURITY 016_dhcpd</title>
      <link>http://www.openbsd.org/errata40.html#016_dhcpd</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>October 8, 2007</pubDate>
      <description><![CDATA[
 Malicious DHCP clients could cause dhcpd(8) to corrupt its stack<br> A DHCP client that claimed to require a maximum message size less than the minimum IP MTU could cause dhcpd(8) to overwrite stack memory. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/016_dhcpd.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>015 SECURITY 015_file</title>
      <link>http://www.openbsd.org/errata40.html#015_file</link>
      <category>SECURITY</category>
      <architecture>All Architectures</architecture>
      <pubDate>July 9, 2007</pubDate>
      <description><![CDATA[
 Fix possible heap overflow in file(1), aka CVE-2007-1536.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/015_file.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>014 STABILITY 014_xorg</title>
      <link>http://www.openbsd.org/errata40.html#014_xorg</link>
      <category>STABILITY</category>
      <architecture>All Architectures</architecture>
      <pubDate>May 9, 2007</pubDate>
      <description><![CDATA[
 A malicious client can cause a division by zero.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/014_xorg.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>013 STABILITY 013_altivec</title>
      <link>http://www.openbsd.org/errata40.html#013_altivec</link>
      <category>STABILITY</category>
      <architecture>PowerPC</architecture>
      <pubDate>April 26, 2007</pubDate>
      <description><![CDATA[
 An unhandled AltiVec assist exception can cause a kernel panic.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/macppc/013_altivec.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>012 SECURITY 012_route6</title>
      <link>http://www.openbsd.org/errata40.html#012_route6</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 23, 2007</pubDate>
      <description><![CDATA[
 IPv6 type 0 route headers can be used to mount a DoS attack against hosts and networks.  This is a design flaw in IPv6 and not a bug in OpenBSD.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/012_route6.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>011 SECURITY 011_xorg</title>
      <link>http://www.openbsd.org/errata40.html#011_xorg</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 4, 2007</pubDate>
      <description><![CDATA[
 Multiple vulnerabilities have been discovered in X.Org.<br> XC-MISC extension ProcXCMiscGetXIDList memory corruption vulnerability, BDFFont parsing integer overflow vulnerability, fonts.dir file parsing integer overflow vulnerability, multiple integer overflows in the XGetPixel() and XInitImage functions in ImUtil.c. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003">CVE-2007-1003</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1351">CVE-2007-1351</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1352">CVE-2007-1352</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667">CVE-2007-1667</a>. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/011_xorg.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>010 SECURITY m_dup1</title>
      <link>http://www.openbsd.org/errata40.html#m_dup1</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>March 7, 2007</pubDate>
      <description><![CDATA[
 <strong>2nd revision, March 17, 2007</strong><br> Incorrect mbuf handling for ICMP6 packets.<br> Using <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=pf&sektion=4">pf(4)</a> to avoid the problem packets is an effective workaround until the patch can be installed.<br> Use "block in inet6" in /etc/pf.conf <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/010_m_dup1.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>009 INTEROPERABILITY timezone</title>
      <link>http://www.openbsd.org/errata40.html#timezone</link>
      <category>INTEROPERABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>February 4, 2007</pubDate>
      <description><![CDATA[
 A US daylight saving time rules change takes effect in 2007. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/009_timezone.patch"> A source code patch exists which syncs the timezone data files with tzdata2007a</a>.<br>
]]></description>
    </item>

    <item>
      <title>008 RELIABILITY icmp6</title>
      <link>http://www.openbsd.org/errata40.html#icmp6</link>
      <category>RELIABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>January 16, 2007</pubDate>
      <description><![CDATA[
 Under some circumstances, processing an ICMP6 echo request would cause the kernel to enter an infinite loop. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/008_icmp6.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>007 SECURITY agp</title>
      <link>http://www.openbsd.org/errata40.html#agp</link>
      <category>SECURITY</category>
      <architecture>i386 only</architecture>
      <pubDate>January 3, 2007</pubDate>
      <description><![CDATA[
 Insufficient validation in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=vga&amp;sektion=4">vga(4)</a> may allow an attacker to gain root privileges if the kernel is compiled with <tt>option PCIAGP</tt> and the actual device is not an AGP device. The <tt>PCIAGP</tt> option is present by default on i386 kernels only. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/i386/007_agp.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>006 FTP DISTRIBUTION ERROR ports-tar</title>
      <link>http://www.openbsd.org/errata40.html#ports-tar</link>
      <category>FTP DISTRIBUTION ERROR</category>
      <architecture>All architectures</architecture>
      <pubDate>December 4, 2006</pubDate>
      <description><![CDATA[
 The <strong>src.tar.gz</strong> and <strong>ports.tar.gz</strong> archives released on FTP were created incorrectly, a week after the 4.0 release. The archives on the CD sets are correct; this only affects people who downloaded them from a <a href="ftp.html">mirror</a>. <br> The archives have been corrected. The correct MD5 of <a href="ftp://ftp.openbsd.org/pub/OpenBSD/4.0/ports.tar.gz"> ports.tar.gz</a> is eff352b4382a7fb7ffce1e8b37e9eb56, and for <a href="ftp://ftp.openbsd.org/pub/OpenBSD/4.0/src.tar.gz"> src.tar.gz</a> it is b8d7a0dc6f3d27a5377a23d69c40688e. <br>
]]></description>
    </item>

    <item>
      <title>005 SECURITY ldso</title>
      <link>http://www.openbsd.org/errata40.html#ldso</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>November 19, 2006</pubDate>
      <description><![CDATA[
 The ELF <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ld.so&amp;sektion=1">ld.so(1)</a> fails to properly sanitize the environment. There is a potential localhost security problem in cases we have not found yet.  This patch applies to all ELF-based systems (m68k, m88k, and vax are a.out-based systems). <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/005_ldso.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>004 RELIABILITY arc</title>
      <link>http://www.openbsd.org/errata40.html#arc</link>
      <category>RELIABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>November 7, 2006</pubDate>
      <description><![CDATA[
 Due to a bug in the <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=arc&amp;sektion=4">arc(4)</a> RAID driver the driver will not properly synchronize the cache to the logical volumes upon system shut down. The result being that the mounted file systems within the logical volumes will not be properly marked as being clean and fsck will be run for the subsequent boot up. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/004_arc.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>003 SECURITY systrace</title>
      <link>http://www.openbsd.org/errata40.html#systrace</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>November 4, 2006</pubDate>
      <description><![CDATA[
 Fix for an integer overflow in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=systrace&amp;sektion=4">systrace(4)</a>'s STRIOCREPLACE support, found by Chris Evans. This could be exploited for DoS, limited kmem reads or local privilege escalation. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/003_systrace.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>002 SECURITY openssl2</title>
      <link>http://www.openbsd.org/errata40.html#openssl2</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>November 4, 2006</pubDate>
      <description><![CDATA[
 Several problems have been found in OpenSSL. While parsing certain invalid ASN.1 structures an error condition is mishandled, possibly resulting in an infinite loop. A buffer overflow exists in the SSL_get_shared_ciphers function. A NULL pointer may be dereferenced in the SSL version 2 client code. In addition, many applications using OpenSSL do not perform any validation of the lengths of public keys being used. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937">CVE-2006-2937</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738">CVE-2006-3738</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343">CVE-2006-4343</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940">CVE-2006-2940</a> <br>  <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/002_openssl.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>001 SECURITY httpd</title>
      <link>http://www.openbsd.org/errata40.html#httpd</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>November 4, 2006</pubDate>
      <description><![CDATA[
 <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&amp;sektion=8">httpd(8)</a> does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3918">CVE-2006-3918</a>  <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/001_httpd.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

  </channel>
</rss>
