Skip to content

Commit

Permalink
do the first half of the 3.3 movearound
Browse files Browse the repository at this point in the history
  • Loading branch information
deraadt committed Mar 26, 2003
1 parent aefee37 commit a7a37a7
Show file tree
Hide file tree
Showing 42 changed files with 1,683 additions and 1,276 deletions.
4 changes: 2 additions & 2 deletions 31.html
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ <h3><font color="#0000e0">
<li>Go to the <font color="#e00000">pub/OpenBSD/3.1/</font> directory on
one of the mirror sites.
<li>Briefly read the rest of this document.
<li>Have a look at <a href="errata.html">The 3.1 Errata page</a> for a list
<li>Have a look at <a href="errata31.html">The 3.1 Errata page</a> for a list
of bugs and workarounds.
<li>See a <a href="plus31.html">detailed log of changes</a> between the
3.0 and 3.1 releases.
Expand Down Expand Up @@ -421,7 +421,7 @@ <h3><font color="#0000e0">Ports Tree</font></h3>
<a href="index.html"><img height="24" width="24" src="back.gif" border="0"
alt="OpenBSD"></a>
<a href=mailto:[email protected]>[email protected]</a>
<br><small>$OpenBSD: 31.html,v 1.13 2002/10/24 20:00:19 jufi Exp $</small>
<br><small>$OpenBSD: 31.html,v 1.14 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
4 changes: 2 additions & 2 deletions 32.html
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ <h3><font color="#0000e0">
<li>Go to the <font color="#e00000">pub/OpenBSD/3.2/</font> directory on
one of the mirror sites.
<li>Briefly read the rest of this document.
<li>Have a look at <a href="errata.html">The 3.2 Errata page</a> for a list
<li>Have a look at <a href="errata32.html">The 3.2 Errata page</a> for a list
of bugs and workarounds.
<li>See a <a href="plus32.html">detailed log of changes</a> between the
3.1 and 3.2 releases.
Expand Down Expand Up @@ -386,7 +386,7 @@ <h3><font color="#0000e0">Ports Tree</font></h3>
alt="OpenBSD"></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>
$OpenBSD: 32.html,v 1.22 2003/01/13 01:06:08 miod Exp $
$OpenBSD: 32.html,v 1.23 2003/03/26 01:16:39 deraadt Exp $
</small>

</body>
Expand Down
6 changes: 2 additions & 4 deletions 33.html
Original file line number Diff line number Diff line change
Expand Up @@ -44,11 +44,9 @@ <h3><font color="#0000e0">
<li>Go to the <font color="#e00000">pub/OpenBSD/3.3/</font> directory on
one of the mirror sites.
<li>Briefly read the rest of this document.
<!-- change to errata33.html when available -->
<li>Have a look at <a href="errata.html">The 3.3 Errata page</a> for a list
of bugs and workarounds.
<!-- change ALL refs to plus.html to plus33.html when available -->
<li>See a <a href="plus.html">detailed log of changes</a> between the
<li>See a <a href="plus33.html">detailed log of changes</a> between the
3.2 and 3.3 releases.
</ul>
</font></h3>
Expand Down Expand Up @@ -371,7 +369,7 @@ <h3><font color="#0000e0">Ports Tree</font></h3>
alt="OpenBSD"></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>
$OpenBSD: 33.html,v 1.13 2003/03/26 01:13:50 miod Exp $
$OpenBSD: 33.html,v 1.14 2003/03/26 01:16:39 deraadt Exp $
</small>

</body>
Expand Down
127 changes: 8 additions & 119 deletions errata.html
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>OpenBSD 3.2 errata</title>
<title>OpenBSD 3.3 errata</title>
<link rev=made href="mailto:[email protected]">
<meta name="resource-type" content="document">
<meta name="description" content="the OpenBSD CD errata page">
Expand All @@ -14,7 +14,7 @@

<a href="index.html"><img alt="[OpenBSD]" height="30" width="141" src="images/smalltitle.gif" border="0"></a>
<h2><font color="#0000e0">
This is the OpenBSD 3.2 release errata &amp; patch list:
This is the OpenBSD 3.3 release errata &amp; patch list:

</font></h2>

Expand All @@ -33,7 +33,8 @@ <h2><font color="#0000e0">
<a href="errata28.html">2.8</a>,
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>.
<a href="errata31.html">3.1</a>,
<a href="errata32.html">3.2</a>.
<br>
<hr>

Expand All @@ -53,120 +54,7 @@ <h2><font color="#0000e0">
<a name=all></a>
<li><h3><font color="#e00000">All architectures</font></h3>
<ul>
<a name=kerberos></a>
<li><font color="#009000"><strong>013: SECURITY FIX: March 24, 2003</strong></font><br>
A cryptographic weaknesses in the Kerberos v4 protocol can be exploited
on Kerberos v5 as well.
<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/013_kerberos.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=kpr></a>
<li><font color="#009000"><strong>012: SECURITY FIX: March 19, 2003</strong></font><br>
OpenSSL is vulnerable to an extension of the ``Bleichenbacher'' attack designed
by Czech researchers Klima, Pokorny and Rosa.
<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/012_kpr.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=blinding></a>
<li><font color="#009000"><strong>011: SECURITY FIX: March 18, 2003</strong></font><br>
Various SSL and TLS operations in OpenSSL are vulnerable to timing attacks.
<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/011_blinding.patch">An
``RSA blinding'' source code patch exists which remedies the problem</a>.
<p>
<a name=lprm></a>
<li><font color="#009000"><strong>010: SECURITY FIX: March 5, 2003</strong></font><br>
A fix for an
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lprm&amp;sektion=1">lprm(1)</a>
bug made in 1996 contains an error that could lead to privilege escalation.
For OpenBSD 3.2 the impact is limited since
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lprm&amp;sektion=1">lprm(1)</a>
is setuid daemon, not setuid root.
<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=sendmail></a>
<li><font color="#009000"><strong>009: SECURITY FIX: March 3, 2003</strong></font><br>
A buffer overflow in the envelope comments processing in
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sendmail&amp;sektion=8">sendmail(8)</a>
may allow an attacker to gain root privileges.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/009_sendmail.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=httpd></a>
<li><font color="#009000"><strong>008: SECURITY FIX: February 25, 2003</strong></font><br>
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=httpd&amp;sektion=8">httpd(8)</a> leaks file inode numbers via ETag header as well as child PIDs in multipart MIME boundary generation. This could lead, for example, to NFS exploitation because it uses inode numbers as part of the file handle.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/008_httpd.patch">A source code patch exists which fixes these two issues</a>.
<p>
<a name=ssl></a>
<li><font color="#009000"><strong>007: SECURITY FIX: February 22, 2003</strong></font><br>
In
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssl&amp;sektion=8">ssl(8)</a> an information leak can occur via timing by performing a MAC computation
even if incorrect block cipher padding has been found, this is a
countermeasure. Also, check for negative sizes in memory allocation routines.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/007_ssl.patch">A
source code patch exists which fixes these two issues</a>.
<p>
<a name=cvs></a>
<li><font color="#009000"><strong>006: SECURITY FIX: January 20, 2003</strong></font><br>
A double free in
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=cvs&amp;sektion=1">cvs(1)</a>
could allow an attacker to execute code with the privileges of the
user running cvs. This is only an issue when the cvs command is
being run on a user's behalf as a different user. This means that,
in most cases, the issue only exists for cvs configurations that use
the <em>pserver</em> client/server connection method.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/006_cvs.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=named></a>
<li><font color="#009000"><strong>005: SECURITY FIX: November 14, 2002</strong></font><br>
A buffer overflow in
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=named&amp;sektion=8">named(8)</a>
could allow an attacker to execute code with the privileges of named.
On OpenBSD, named runs as a non-root user in a chrooted environment
which mitigates the effects of this bug.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/005_named.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=pool></a>
<li><font color="#009000"><strong>004: RELIABILITY FIX: November 6, 2002</strong></font><br>
A logic error in the
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=pool&amp;sektion=9">pool</a>
kernel memory allocator could cause memory corruption in low-memory situations,
causing the system to crash.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/004_pool.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=smrsh></a>
<li><font color="#009000"><strong>003: SECURITY FIX: November 6, 2002</strong></font><br>
An attacker can bypass the restrictions imposed by sendmail's restricted shell,
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=smrsh&amp;sektion=8">smrsh(8)</a>,
and execute arbitrary commands with the privileges of his own account.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/003_smrsh.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=pfbridge></a>
<li><font color="#009000"><strong>002: RELIABILITY FIX: November 6, 2002</strong></font><br>
Network
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=bridge&amp;sektion=4">bridges</a>
running
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=pf&amp;sektion=4">pf</a>
with scrubbing enabled could cause mbuf corruption,
causing the system to crash.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/002_pfbridge.patch">A
source code patch exists which remedies the problem</a>.
<p>
<a name=kadmin></a>
<li><font color="#009000"><strong>001: SECURITY FIX: October 21, 2002</strong></font><br>
A buffer overflow can occur in the
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=kadmind&amp;sektion=8">kadmind(8)</a>
daemon, leading to possible remote crash or exploit.<br>
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/001_kadmin.patch">A source code patch exists which remedies the problem</a>.
<p>
<li>No problems identified yet.
</ul>
<p>
<a name=i386></a>
Expand Down Expand Up @@ -247,13 +135,14 @@ <h2><font color="#0000e0">
<a href="errata28.html">2.8</a>,
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>.
<a href="errata31.html">3.1</a>,
<a href="errata32.html">3.2</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata.html,v 1.439 2003/03/24 19:21:06 millert Exp $</small>
<br><small>$OpenBSD: errata.html,v 1.440 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
8 changes: 5 additions & 3 deletions errata21.html
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,8 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>
<hr>

Expand Down Expand Up @@ -225,13 +226,14 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata21.html,v 1.28 2003/03/06 21:44:07 naddy Exp $</small>
<br><small>$OpenBSD: errata21.html,v 1.29 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
8 changes: 5 additions & 3 deletions errata22.html
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,8 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>
<hr>

Expand Down Expand Up @@ -368,13 +369,14 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata22.html,v 1.37 2003/03/06 21:44:07 naddy Exp $</small>
<br><small>$OpenBSD: errata22.html,v 1.38 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
8 changes: 5 additions & 3 deletions errata23.html
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,8 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>
<hr>

Expand Down Expand Up @@ -377,13 +378,14 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata23.html,v 1.28 2003/03/06 21:44:07 naddy Exp $</small>
<br><small>$OpenBSD: errata23.html,v 1.29 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
8 changes: 5 additions & 3 deletions errata24.html
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,8 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>
<hr>

Expand Down Expand Up @@ -320,13 +321,14 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata24.html,v 1.24 2003/03/06 21:44:07 naddy Exp $</small>
<br><small>$OpenBSD: errata24.html,v 1.25 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
8 changes: 5 additions & 3 deletions errata25.html
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,8 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>
<hr>

Expand Down Expand Up @@ -244,13 +245,14 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata25.html,v 1.21 2003/03/06 21:44:07 naddy Exp $</small>
<br><small>$OpenBSD: errata25.html,v 1.22 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
8 changes: 5 additions & 3 deletions errata26.html
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,8 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>
<hr>

Expand Down Expand Up @@ -335,13 +336,14 @@ <h2><font color="#0000e0">
<a href="errata29.html">2.9</a>,
<a href="errata30.html">3.0</a>,
<a href="errata31.html">3.1</a>,
<a href="errata.html">3.2</a>.
<a href="errata32.html">3.2</a>,
<a href="errata.html">3.3</a>.
<br>

<hr>
<a href=index.html><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
<a href="mailto:[email protected]">[email protected]</a>
<br><small>$OpenBSD: errata26.html,v 1.24 2003/03/06 21:44:07 naddy Exp $</small>
<br><small>$OpenBSD: errata26.html,v 1.25 2003/03/26 01:16:39 deraadt Exp $</small>

</body>
</html>
Loading

0 comments on commit a7a37a7

Please sign in to comment.