<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
  <channel>
    <title>OpenBSD 41 Errata</title>
    <link>http://www.openbsd.org/errata41.html</link>
    <description>OpenBSD 41 Errata</description>
    <language>en-us</language>
    <managingEditor>mike@erdelynet.com</managingEditor>

    <image>
      <title>erdelynet.com</title>
      <url>http://erdelynet.com/images/puffy96x83.gif</url>
      <link>http://www.openbsd.org/errata41.html</link>
      <width>96</width>
      <height>83</height>
      <description>OpenBSD 41 Errata</description>
    </image>

    <item>
      <title>016 SECURITY 016_openssh2</title>
      <link>http://www.openbsd.org/errata41.html#016_openssh2</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 3, 2008</pubDate>
      <description><![CDATA[
 Avoid possible hijacking of X11-forwarded connections with sshd(8) by refusing to listen on a port unless all address families bind successfully.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/016_openssh2.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>015 SECURITY 015_openssh</title>
      <link>http://www.openbsd.org/errata41.html#015_openssh</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>March 30, 2008</pubDate>
      <description><![CDATA[
 sshd(8) would execute ~/.ssh/rc even when a sshd_config(5) <em>ForceCommand</em> directive was in effect, allowing users with write access to this file to execute arbitrary commands. This behaviour was documented, but was an unsafe default and an extra hassle for administrators.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/015_openssh.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>014 SECURITY 014_ppp</title>
      <link>http://www.openbsd.org/errata41.html#014_ppp</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>March 7, 2008</pubDate>
      <description><![CDATA[
 Buffer overflow in ppp command prompt parsing.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/014_ppp.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>013 RELIABILITY 013_tcprespond</title>
      <link>http://www.openbsd.org/errata41.html#013_tcprespond</link>
      <category>RELIABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>February 22, 2008</pubDate>
      <description><![CDATA[
 Incorrect assumptions in tcp_respond can lead to a kernel panic.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/013_tcprespond.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>012 SECURITY 012_xorg</title>
      <link>http://www.openbsd.org/errata41.html#012_xorg</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>February 8, 2008</pubDate>
      <description><![CDATA[
 <strong>2nd revision, February 10, 2008</strong><br> Multiple vulnerabilities have been discovered in X.Org.<br> XFree86 Misc extension out of bounds array index, File existence disclosure, Xinput extension memory corruption, TOG-cup extension memory corruption, MIT-SHM and EVI extensions integer overflows, PCF Font parser buffer overflow. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5760">CVE-2007-5760</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5958">CVE-2007-5958</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6427">CVE-2007-6427</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6428">CVE-2007-6428</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6429">CVE-2007-6429</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0006">CVE-2008-0006</a>. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/012_xorg.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>011 SECURITY 011_openssl</title>
      <link>http://www.openbsd.org/errata41.html#011_openssl</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>October 10, 2007</pubDate>
      <description><![CDATA[
 The SSL_get_shared_ciphers() function in OpenSSL contains an off-by-one overflow. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/011_openssl.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>010 SECURITY 010_dhcpd</title>
      <link>http://www.openbsd.org/errata41.html#010_dhcpd</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>October 8, 2007</pubDate>
      <description><![CDATA[
 Malicious DHCP clients could cause dhcpd(8) to corrupt its stack<br> A DHCP client that claimed to require a maximum message size less than the minimum IP MTU could cause dhcpd(8) to overwrite stack memory. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/010_dhcpd.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>009 SECURITY 009_file</title>
      <link>http://www.openbsd.org/errata41.html#009_file</link>
      <category>SECURITY</category>
      <architecture>All Architectures</architecture>
      <pubDate>July 9, 2007</pubDate>
      <description><![CDATA[
 Fix possible heap overflow in file(1), aka CVE-2007-1536.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/009_file.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>008 STABILITY 008_xorg</title>
      <link>http://www.openbsd.org/errata41.html#008_xorg</link>
      <category>STABILITY</category>
      <architecture>All Architectures</architecture>
      <pubDate>May 9, 2007</pubDate>
      <description><![CDATA[
 A malicious client can cause a division by zero.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/008_xorg.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>007 RELIABILITY 007_kroute</title>
      <link>http://www.openbsd.org/errata41.html#007_kroute</link>
      <category>RELIABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 30, 2007</pubDate>
      <description><![CDATA[
 Link state is not correctly tracked in ospfd and ripd.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/007_kroute.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>006 STABILITY 006_altivec</title>
      <link>http://www.openbsd.org/errata41.html#006_altivec</link>
      <category>STABILITY</category>
      <architecture>PowerPC</architecture>
      <pubDate>April 27, 2007</pubDate>
      <description><![CDATA[
 An unhandled AltiVec assist exception can cause a kernel panic.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/macppc/006_altivec.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>005 SECURITY 005_route6</title>
      <link>http://www.openbsd.org/errata41.html#005_route6</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 27, 2007</pubDate>
      <description><![CDATA[
 IPv6 type 0 route headers can be used to mount a DoS attack against hosts and networks.  This is a design flaw in IPv6 and not a bug in OpenBSD.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/005_route6.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>004 SECURITY 004_xorg</title>
      <link>http://www.openbsd.org/errata41.html#004_xorg</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 27, 2007</pubDate>
      <description><![CDATA[
 Multiple vulnerabilities have been discovered in X.Org.<br> XC-MISC extension ProcXCMiscGetXIDList memory corruption vulnerability, BDFFont parsing integer overflow vulnerability, fonts.dir file parsing integer overflow vulnerability, multiple integer overflows in the XGetPixel() and XInitImage functions in ImUtil.c. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003">CVE-2007-1003</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1351">CVE-2007-1351</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1352">CVE-2007-1352</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1667">CVE-2007-1667</a>. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/004_xorg.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>003 RELIABILITY 003_spamd</title>
      <link>http://www.openbsd.org/errata41.html#003_spamd</link>
      <category>RELIABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 27, 2007</pubDate>
      <description><![CDATA[
 Bugs found in the spamd sychronization mechanism could cause corrupted databases.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/003_spamd.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>002 STABILITY 002_splnet</title>
      <link>http://www.openbsd.org/errata41.html#002_splnet</link>
      <category>STABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 27, 2007</pubDate>
      <description><![CDATA[
 Incorrect spl level can lead to panics under heavy kqueue usage.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/002_splnet.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>001 SECURITY 001_mbuf</title>
      <link>http://www.openbsd.org/errata41.html#001_mbuf</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 27, 2007</pubDate>
      <description><![CDATA[
 Incorrect mbuf handling for ICMP6 packets.<br> Using <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=pf&sektion=4">pf(4)</a> to avoid the problem packets is an effective workaround until the patch can be installed.<br> Use "block in inet6" in /etc/pf.conf <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/001_mbuf.patch"> A source code patch exists which remedies this problem</a>.<br> 
]]></description>
    </item>

  </channel>
</rss>
