<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-12605</id>
	<title>Nabble - openbsd user - security-announce</title>
	<updated>2009-11-26T01:41:59Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/openbsd-user---security-announce-f12605.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/openbsd-user---security-announce-f12605.html" />
	<subtitle type="html">Security announcements. This low volume list receives OpenBSD security advisories and pointers to security patches as they become available.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26527045</id>
	<title>CVE-2009-3555: SSL/TLS renegotiation MITM vulnerability</title>
	<published>2009-11-26T01:41:59Z</published>
	<updated>2009-11-26T01:41:59Z</updated>
	<author>
		<name>Stuart Henderson-8</name>
	</author>
	<content type="html">The SSL/TLS protocol is subject to man-in-the-middle attacks
&lt;br&gt;related to renegotiation (described in draft-ietf-tls-renegotiation-00)
&lt;br&gt;allowing a MITM to inject chosen plaintext to the beginning of the
&lt;br&gt;application data. Practical attacks exist against HTTPS and possibly
&lt;br&gt;other protocols.
&lt;br&gt;&lt;br&gt;In -current, OpenSSL's ability to accept renegotiations has been
&lt;br&gt;disabled by default. Patches are available for OpenBSD 4.6 and 4.5:
&lt;br&gt;&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/010_openssl.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/004_openssl.patch
&lt;br&gt;&lt;br&gt;These are also available in the 4.5 and 4.6 -stable branches.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CVE-2009-3555%3A-SSL-TLS-renegotiation-MITM-vulnerability-tp26527045p26527045.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25749045</id>
	<title>OpenBSD patch: XMM exceptions incorrectly handled in i386 kernel</title>
	<published>2009-10-05T04:21:27Z</published>
	<updated>2009-10-05T04:21:27Z</updated>
	<author>
		<name>Joel Sing-2</name>
	</author>
	<content type="html">XMM exceptions are incorrectly handled in the OpenBSD/i386 kernel, resulting
&lt;br&gt;in a kernel panic that can be triggered by a local user.
&lt;br&gt;&lt;br&gt;This issue has been fixed in -current. Source code patches are available for
&lt;br&gt;OpenBSD 4.4, 4.5 and 4.6.
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.6:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/i386/002_xmm.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.5:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/i386/008_xmm.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.4:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/i386/015_xmm.patch
&lt;br&gt;&lt;br&gt;These patches are also available in the OPENBSD_4_6, OPENBSD_4_5 and
&lt;br&gt;OPENBSD_4_4 patch branches.
&lt;br&gt;&lt;br&gt;Thanks to Slava Pestov for reporting this issue.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenBSD-patch%3A-XMM-exceptions-incorrectly-handled-in-i386-kernel-tp25749045p25749045.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23322423</id>
	<title>(no subject)</title>
	<published>2009-04-30T10:21:50Z</published>
	<updated>2009-04-30T10:21:50Z</updated>
	<author>
		<name>Bob Beck-3</name>
	</author>
	<content type="html">&amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Users are cautioned about rogue ftp sites claiming to have OpenBSD.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The best place to get OpenBSD is from an official CD set, produced in
&lt;br&gt;a secured location
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It has come to our attention that some ftp sites (ftp.kd85.com) which
&lt;br&gt;are not official OpenBSD mirrors are purporting to serve OpenBSD 4.5
&lt;br&gt;at this time. We have noted that what is actually present in the 4.5
&lt;br&gt;directory is not 4.5, but rather a late development cycle snapshot which
&lt;br&gt;they have moved into place claiming it is 4.5. 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;	While we have no problem with anyone mirroring OpenBSD for the good 
&lt;br&gt;of the user community, we do believe that people who offer up the wrong
&lt;br&gt;thing are being deceptive and will hurt the userbase - particularly when
&lt;br&gt;the packages being offered up are not the release versions. 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;	please ensure you look at &lt;a href=&quot;http://www.openbsd.org/ftp.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openbsd.org/ftp.html&lt;/a&gt;&amp;nbsp;when
&lt;br&gt;choosing to do an ftp install, and don't be fooled by someone &amp;quot;phishing&amp;quot;
&lt;br&gt;for your ftp traffic.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/%28no-subject%29-tp23322423p23322423.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23006774</id>
	<title>OpenBSD patch: pf nat/rdr of crafted datagram panics kernel</title>
	<published>2009-04-11T16:46:24Z</published>
	<updated>2009-04-11T16:46:24Z</updated>
	<author>
		<name>Joel Sing-2</name>
	</author>
	<content type="html">When pf attempts to perform translation on a specially crafted IP datagram
&lt;br&gt;a null pointer dereference will occur, resulting in a kernel panic.
&lt;br&gt;In certain configurations this may be triggered by a remote attacker.
&lt;br&gt;&lt;br&gt;Restricting translation rules to protocols that are specific to the IP version
&lt;br&gt;in use is an effective workaround until the patch can be installed. As an
&lt;br&gt;example, for IPv4 nat/binat/rdr rules you can use:
&lt;br&gt;&lt;br&gt;nat/rdr ... inet proto { tcp udp icmp } ...
&lt;br&gt;&lt;br&gt;Or for IPv6 nat/binat/rdr rules you can use:
&lt;br&gt;&lt;br&gt;nat/rdr ... inet6 proto { tcp udp icmp6 } ...
&lt;br&gt;&lt;br&gt;This issue has been fixed in -current. Source code patches are available for
&lt;br&gt;OpenBSD 4.3, 4.4 and 4.5.
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.5:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_pf.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.4:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/common/013_pf.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.3:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/013_pf.patch
&lt;br&gt;&lt;br&gt;These patches are also available in the OPENBSD_4_5, OPENBSD_4_4 and
&lt;br&gt;OPENBSD_4_3 patch branches.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenBSD-patch%3A-pf-nat-rdr-of-crafted-datagram-panics-kernel-tp23006774p23006774.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22945516</id>
	<title>Correction: OpenSSL CVE-2009-0590 and CVE-2009-0789: ASN.1 invalid memory access</title>
	<published>2009-04-08T00:21:42Z</published>
	<updated>2009-04-08T00:21:42Z</updated>
	<author>
		<name>Damien Miller</name>
	</author>
	<content type="html">On Wed, 8 Apr 2009, Damien Miller wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Patch for OpenBSD 4.5:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_openssl.patch
&lt;br&gt;&lt;br&gt;Correction, this should be:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/001_openssl.patch
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenSSL-CVE-2009-0590-and-CVE-2009-0789%3A-ASN.1-invalid-memory-access-tp22942293p22945516.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22942293</id>
	<title>OpenSSL CVE-2009-0590 and CVE-2009-0789: ASN.1 invalid memory access</title>
	<published>2009-04-07T19:53:23Z</published>
	<updated>2009-04-07T19:53:23Z</updated>
	<author>
		<name>Damien Miller-4</name>
	</author>
	<content type="html">&lt;br&gt;A number of exploitable flaws in OpenSSL's ASN.1 handling code have been
&lt;br&gt;found. These errors permit denial-of-service (crashing) of applications
&lt;br&gt;that use OpenSSL's libcrypto to parse or print ASN.1 objects.
&lt;br&gt;&lt;br&gt;The vulnerabilities have been designated CVE-2009-0590 and CVE-2009-0789
&lt;br&gt;and are described in more detail in OpenSSL's security advisory:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org/news/secadv_20090325.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/news/secadv_20090325.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;Please note that the other, more serious issue described in the OpenSSL
&lt;br&gt;advisory &amp;quot;Incorrect Error Checking During CMS verification&amp;quot; does not
&lt;br&gt;affect OpenBSD as we have not enabled the offending code.
&lt;br&gt;&lt;br&gt;Source code patches are available for OpenBSD 4.3, 4.4 and 4.5. OpenBSD
&lt;br&gt;-current has been updated to OpenSSL 0.9.8k, which is not vulnerable.
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.5:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.5/common/002_openssl.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.4:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/common/012_openssl.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.3:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/012_openssl.patch
&lt;br&gt;&lt;br&gt;These patches are also available in the OPENBSD_4_5, OPENBSD_4_4 and
&lt;br&gt;OPENBSD_4_3 patch branches.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenSSL-CVE-2009-0590-and-CVE-2009-0789%3A-ASN.1-invalid-memory-access-tp22942293p22942293.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22169924</id>
	<title>Sudo CVE 2009-0034: possible elevated access</title>
	<published>2009-02-23T12:20:51Z</published>
	<updated>2009-02-23T12:20:51Z</updated>
	<author>
		<name>Todd C. Miller</name>
	</author>
	<content type="html">Summary:
&lt;br&gt;&amp;nbsp; &amp;nbsp; A bug was introduced in Sudo's group matching code in version
&lt;br&gt;&amp;nbsp; &amp;nbsp; 1.6.9 when support for matching based on the supplemental group
&lt;br&gt;&amp;nbsp; &amp;nbsp; vector was added. &amp;nbsp;This bug may allow certain users listed in
&lt;br&gt;&amp;nbsp; &amp;nbsp; the sudoers file to run a command as a different user than their
&lt;br&gt;&amp;nbsp; &amp;nbsp; access rule specifies.
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.3:
&lt;br&gt;&amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/011_sudo.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.4:
&lt;br&gt;&amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/common/011_sudo.patch
&lt;br&gt;&lt;br&gt;These patches are also available in the OPENBSD_4_3 and OPENBSD_4_4
&lt;br&gt;stable CVS branches. &amp;nbsp;OpenBSD-current is not affected.
&lt;br&gt;&lt;br&gt;Details:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Given a sudoers rule like the following:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bob ALL=(%users) ALL
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; user bob should only be able to run commands as a user that
&lt;br&gt;&amp;nbsp; &amp;nbsp; is a member of the Unix group users.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; However, due to the bug, if bob is himself a member of users,
&lt;br&gt;&amp;nbsp; &amp;nbsp; he will actually be able to run a command as any user.
&lt;br&gt;&lt;br&gt;Impact:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The bug only impacts sudoers configurations where a Unix group
&lt;br&gt;&amp;nbsp; &amp;nbsp; is used in the RunAs list, which is (%users) in the example above.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; For example, the following sudoers rule is not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; by the bug:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bob ALL = ALL
&lt;br&gt;&lt;br&gt;Credit:
&lt;br&gt;&amp;nbsp; &amp;nbsp; This problem was brought to my attention by Harald Koenig.
&lt;br&gt;&lt;br&gt;Background:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Code was added to sudo version 1.7.0 to cache the user's
&lt;br&gt;&amp;nbsp; &amp;nbsp; supplemental group vector and use it in group matches. &amp;nbsp;When
&lt;br&gt;&amp;nbsp; &amp;nbsp; this changed was back-ported to sudo version 1.6.9, the check
&lt;br&gt;&amp;nbsp; &amp;nbsp; to only use the supplemental groups when matching against the
&lt;br&gt;&amp;nbsp; &amp;nbsp; invoking user got dropped.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sudo-CVE-2009-0034%3A-possible-elevated-access-tp22169924p22169924.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21467638</id>
	<title>bind CVE-2009-0025: incorrect DSA verification checks</title>
	<published>2009-01-14T14:45:05Z</published>
	<updated>2009-01-14T14:45:05Z</updated>
	<author>
		<name>Damien Miller</name>
	</author>
	<content type="html">Some exploitable logic errors have been found in the bind nameserver's
&lt;br&gt;use of OpenSSL DSA verification functions. These errors may permit an
&lt;br&gt;attacker to bypass validation of DSA DNSSEC signatures.
&lt;br&gt;&lt;br&gt;This vulnerability has been designated CVE-2009-0025. More information
&lt;br&gt;is available from the ISC at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;https://www.isc.org/node/373&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.isc.org/node/373&lt;/a&gt;&lt;br&gt;&lt;br&gt;Source code patches are available for OpenBSD 4.3 and 4.4. -current has
&lt;br&gt;had an identical fix applied.
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.3:
&lt;br&gt;&amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/008_bind.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.4:
&lt;br&gt;&amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/common/008_bind.patch
&lt;br&gt;&lt;br&gt;These patches are also available in the OPENBSD_4_3 and OPENBSD_4_4
&lt;br&gt;stable CVS branches.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/bind-CVE-2009-0025%3A-incorrect-DSA-verification-checks-tp21467638p21467638.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21372424</id>
	<title>OpenSSL CVE-2008-5077: Incorrect checks for malformed signatures</title>
	<published>2009-01-09T05:12:40Z</published>
	<updated>2009-01-09T05:12:40Z</updated>
	<author>
		<name>Damien Miller-4</name>
	</author>
	<content type="html">&lt;br&gt;Some exploitable logic errors have been discovered in OpenSSL versions
&lt;br&gt;prior to 0.9.8j. These errors may permit an attacker to bypass
&lt;br&gt;validation of DSA/ECDSA certificates and conduct a &amp;quot;man in the middle
&lt;br&gt;attack&amp;quot; against SSL/TLS connection that use them. Fortunately, DSA and
&lt;br&gt;ECDSA certificates appear to be rarely used in practice.
&lt;br&gt;&lt;br&gt;This vulnerability has been designated CVE-2008-5077. More information
&lt;br&gt;is available from the OpenSSL project at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://www.openssl.org/news/secadv_20090107.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/news/secadv_20090107.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;Source code patches are available for OpenBSD 4.3 and 4.4. -current has
&lt;br&gt;been updated to OpenSSL 0.9.8j
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.3:
&lt;br&gt;&amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/007_openssl.patch
&lt;br&gt;&lt;br&gt;Patch for OpenBSD 4.4:
&lt;br&gt;&amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.4/common/007_openssl.patch
&lt;br&gt;&lt;br&gt;These patches are also available in the OPENBSD_4_3 and OPENBSD_4_4
&lt;br&gt;stable CVS branches.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenSSL-CVE-2008-5077%3A-Incorrect-checks-for-malformed-signatures-tp21372424p21372424.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-20665967</id>
	<title>Revised: OpenSSH security advisory: cbc.adv</title>
	<published>2008-11-23T13:58:55Z</published>
	<updated>2008-11-23T13:58:55Z</updated>
	<author>
		<name>Damien Miller-2</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;There was an error in the original advisory. The estimate of 32768
&lt;br&gt;attempts to carry out a successful attack is incorrect. The correct
&lt;br&gt;estimate is 11356 attempts. A revised version is now available at:
&lt;br&gt;&lt;a href=&quot;http://www.openssh.com/txt/cbc.adv&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssh.com/txt/cbc.adv&lt;/a&gt;&lt;br&gt;&lt;br&gt;The advisory and its recommendations are otherwise unchanged.
&lt;br&gt;&lt;br&gt;-d
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Revised%3A-OpenSSH-security-advisory%3A-cbc.adv-tp20665967p20665967.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-20622452</id>
	<title>OpenSSH security advisory: cbc.adv</title>
	<published>2008-11-21T02:19:03Z</published>
	<updated>2008-11-21T02:19:03Z</updated>
	<author>
		<name>Damien Miller-2</name>
	</author>
	<content type="html">OpenSSH Security Advisory: cbc.adv
&lt;br&gt;&lt;br&gt;Regarding the &amp;quot;Plaintext Recovery Attack Against SSH&amp;quot; reported as
&lt;br&gt;CPNI-957037[1]:
&lt;br&gt;&lt;br&gt;The OpenSSH team has been made aware of an attack against the SSH
&lt;br&gt;protocol version 2 by researchers at the University of London.
&lt;br&gt;Unfortunately, due to the report lacking any detailed technical
&lt;br&gt;description of the attack and CPNI's unwillingness to share necessary
&lt;br&gt;information, we are unable to properly assess its impact.
&lt;br&gt;&lt;br&gt;Based on the description contained in the CPNI report and a slightly
&lt;br&gt;more detailed description forwarded by CERT this issue appears to be
&lt;br&gt;substantially similar to a known weakness in the SSH binary packet
&lt;br&gt;protocol first described in 2002 by Bellare, Kohno and Namprempre[2].
&lt;br&gt;The new component seems to be an attack that can recover 14 bits of
&lt;br&gt;plaintext with a success probability of 2^-14, though we suspect this
&lt;br&gt;underestimates the work required by a practical attack.
&lt;br&gt;&lt;br&gt;For most SSH usage scenarios, this attack has a very low likelihood of
&lt;br&gt;being carried out successfully - each attempt has a low probability
&lt;br&gt;of success and each failure will cause connection termination with a
&lt;br&gt;fatal error. It is therefore very unlikely for an interactive session
&lt;br&gt;to be usefully attacked using this protocol weakness: an attacker would
&lt;br&gt;expect around 32768 connection-killing attempts before they are likely
&lt;br&gt;to succeed. This level of disruption would certainly be noticed and it
&lt;br&gt;is highly unlikely that any user would retry the connection enough times
&lt;br&gt;for the attack to succeed.
&lt;br&gt;&lt;br&gt;The usage pattern where the attack is most likely to succeed is where an
&lt;br&gt;automated connection is configured to retry indefinitely in the event of
&lt;br&gt;errors. In this case, it might be possible to recover as much as 14 bits
&lt;br&gt;of plaintext per hour (assuming a very fast 10 connections per second).
&lt;br&gt;Implementing a limit on the number of connection retries (e.g. 256) is
&lt;br&gt;sufficient to render the attack infeasible for this case.
&lt;br&gt;&lt;br&gt;AES CTR mode and arcfour ciphers are not vulnerable to this attack at
&lt;br&gt;all. These may be preferentially selected by placing the following
&lt;br&gt;directive in sshd_config and ssh_config:
&lt;br&gt;&lt;br&gt;Ciphers aes128-ctr,aes256-ctr,arcfour256,arcfour,aes128-cbc,aes256-cbc
&lt;br&gt;&lt;br&gt;A future version of OpenSSH may make CTR mode ciphers the default and/or
&lt;br&gt;implement other countermeasures, but at present we do not feel that this
&lt;br&gt;issue is serious enough to make an emergency release.
&lt;br&gt;&lt;br&gt;-d
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt&lt;/a&gt;&lt;br&gt;[2] &lt;a href=&quot;http://www.cs.washington.edu/homes/yoshi/papers/TISSEC04/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cs.washington.edu/homes/yoshi/papers/TISSEC04/&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenSSH-security-advisory%3A-cbc.adv-tp20622452p20622452.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-14761225</id>
	<title>errata 005 for OpenBSD 4.2: local users can provoke a kernel panic</title>
	<published>2008-01-11T09:05:34Z</published>
	<updated>2008-01-11T09:05:34Z</updated>
	<author>
		<name>Henning Brauer-2</name>
	</author>
	<content type="html">Summary:
&lt;br&gt;&amp;nbsp; &amp;nbsp;Improper checks in an ioctl can lead to a kernel panic.
&lt;br&gt;&lt;br&gt;Details:
&lt;br&gt;&amp;nbsp; &amp;nbsp; recently added calls to rtlabel_id2name() for &amp;quot;ifconfig rtlabel&amp;quot; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; did not properly check the return value before using it.
&lt;br&gt;&amp;nbsp; &amp;nbsp; rtlabel_id2name can return NULL if there is no label assigned
&lt;br&gt;&amp;nbsp; &amp;nbsp; or the ID is invalid.
&lt;br&gt;&lt;br&gt;Impact:
&lt;br&gt;&amp;nbsp; &amp;nbsp; local users can cause a kernel panic by using the SIOCGIFRTLABEL
&lt;br&gt;&amp;nbsp; &amp;nbsp; ioctl on interfaces with no route label assigned.
&lt;br&gt;&amp;nbsp; &amp;nbsp; ifconfig does not use that ioctl.
&lt;br&gt;&lt;br&gt;Workaround:
&lt;br&gt;&amp;nbsp; &amp;nbsp; none
&lt;br&gt;&lt;br&gt;Fix:
&lt;br&gt;&amp;nbsp; &amp;nbsp; A fix has been committed to OpenBSD-current and the OpenBSD 4.2-stable
&lt;br&gt;&amp;nbsp; &amp;nbsp; branch.
&lt;br&gt;&amp;nbsp; &amp;nbsp; A patch for OpenBSD 4.2 will appear at the URL below shortly.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.2/common/005_ifrtlabel.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Older OpenBSD versions are not affected.
&lt;br&gt;&lt;br&gt;Credits:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The bug was found by Chris Cappuccio who also provided an initial 
&lt;br&gt;&amp;nbsp; &amp;nbsp; fix. &amp;nbsp;The final fix was done by Henning Brauer.
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (194 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/14761225/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/errata-005-for-OpenBSD-4.2%3A-local-users-can-provoke-a-kernel-panic-tp14761225p14761225.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-13172591</id>
	<title>Security fix for openssl</title>
	<published>2007-10-12T03:39:30Z</published>
	<updated>2007-10-12T03:39:30Z</updated>
	<author>
		<name>Moritz Jodeit-2</name>
	</author>
	<content type="html">Summary:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The SSL_get_shared_ciphers() function in OpenSSL contains an
&lt;br&gt;&amp;nbsp; &amp;nbsp; off-by-one overflow.
&lt;br&gt;&lt;br&gt;Impact:
&lt;br&gt;&amp;nbsp; &amp;nbsp; A client can send a specially prepared list of ciphers to an
&lt;br&gt;&amp;nbsp; &amp;nbsp; application using the SSL_get_shared_ciphers() function from
&lt;br&gt;&amp;nbsp; &amp;nbsp; the OpenSSL library, potentially resulting in remote code
&lt;br&gt;&amp;nbsp; &amp;nbsp; execution.
&lt;br&gt;&lt;br&gt;Fix:
&lt;br&gt;&amp;nbsp; &amp;nbsp; A fix has been committed to OpenBSD-current. &amp;nbsp;Patches are
&lt;br&gt;&amp;nbsp; &amp;nbsp; available for OpenBSD 4.2, 4.1 and 4.0.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.2/common/002_openssl.patch
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/011_openssl.patch
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/017_openssl.patch
&lt;br&gt;&lt;br&gt;Credits:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The bug was found and fixed by Moritz Jodeit (moritz@).
&lt;br&gt;&amp;nbsp; &amp;nbsp; Original Adivsory:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;lt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/480855/30/0/threaded&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/archive/1/480855/30/0/threaded&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Security-fix-for-openssl-tp13172591p13172591.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-13125433</id>
	<title>Security fix for dhcpd</title>
	<published>2007-10-09T15:22:20Z</published>
	<updated>2007-10-09T15:22:20Z</updated>
	<author>
		<name>Todd C. Miller</name>
	</author>
	<content type="html">Summary:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Malicious DHCP clients on the local network could cause dhcpd(8)
&lt;br&gt;&amp;nbsp; &amp;nbsp; to corrupt its stack.
&lt;br&gt;&lt;br&gt;Impact:
&lt;br&gt;&amp;nbsp; &amp;nbsp; A DHCP client with a carefully chosen maximum message size that
&lt;br&gt;&amp;nbsp; &amp;nbsp; is less than the minimum IP MTU could lead to a buffer overflow
&lt;br&gt;&amp;nbsp; &amp;nbsp; in dhcpd(8). &amp;nbsp;This could cause dhcpd(8) to crash or could
&lt;br&gt;&amp;nbsp; &amp;nbsp; potentially result in remote code execution.
&lt;br&gt;&lt;br&gt;Workaround:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Disable dhcpd if it is enabled. &amp;nbsp;Note that OpenBSD does not
&lt;br&gt;&amp;nbsp; &amp;nbsp; ship with dhcpd(8) enabled by default.
&lt;br&gt;&lt;br&gt;Fix:
&lt;br&gt;&amp;nbsp; &amp;nbsp; A fix has been committed to OpenBSD-current. &amp;nbsp;Patches are
&lt;br&gt;&amp;nbsp; &amp;nbsp; available for OpenBSD 4.2, 4.1 and 4.0.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.2/common/001_dhcpd.patch
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/010_dhcpd.patch
&lt;br&gt;&amp;nbsp; &amp;nbsp; ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/016_dhcpd.patch
&lt;br&gt;&lt;br&gt;Credits:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The bug was found by Nahuel Riva and Gerardo Richarte of Core
&lt;br&gt;&amp;nbsp; &amp;nbsp; Security Technologies
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Security-fix-for-dhcpd-tp13125433p13125433.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10147558</id>
	<title>IPv6 Type 0 Route Header Design Flaw</title>
	<published>2007-04-23T12:09:19Z</published>
	<updated>2007-04-23T12:09:19Z</updated>
	<author>
		<name>Marc Balmer</name>
	</author>
	<content type="html">IPv6 type 0 route headers can be used to mount a DoS attack against
&lt;br&gt;hosts and networks. &amp;nbsp;This is a design flaw in IPv6 and not a bug in
&lt;br&gt;OpenBSD.
&lt;br&gt;&lt;br&gt;This problem has been fixed in the OpenBSD CVS repository in the
&lt;br&gt;-current and -stable branches. &amp;nbsp;The -current snapshots of OpenBSD
&lt;br&gt;contain these fixes as well.
&lt;br&gt;&lt;br&gt;It is recommended that users of OpenBSD update their kernel asap
&lt;br&gt;using cvs or manually apply the source code patches listed below.
&lt;br&gt;&lt;br&gt;A source code patch for OpenBSD 4.0-stable can be downloaded from
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/012_route6.patch.
&lt;br&gt;&lt;br&gt;A source code patch for OpenBSD 3.9-stable can be downloaded from
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/022_route6.patch.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/IPv6-Type-0-Route-Header-Design-Flaw-tp10147558p10147558.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-9840530</id>
	<title>Multiple vulnerabilities in X.Org</title>
	<published>2007-04-04T08:29:06Z</published>
	<updated>2007-04-04T08:29:06Z</updated>
	<author>
		<name>Marc Balmer</name>
	</author>
	<content type="html">Multiple vulnerabilities have been discovered in X.Org:
&lt;br&gt;&lt;br&gt;- XC-MISC CVE-2007-1003
&lt;br&gt;&lt;br&gt;&amp;nbsp; XC-MISC Extension ProcXCMiscGetXIDList Memory Corruption
&lt;br&gt;&amp;nbsp; Vulnerability
&lt;br&gt;&lt;br&gt;This vulnerability was discovered by Sean Larsson, iDefense Labs.
&lt;br&gt;&lt;br&gt;&lt;br&gt;- bdf CVE-2007-1351
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;BDFFont Parsing Integer Overflow Vulnerability
&lt;br&gt;&lt;br&gt;The discoverer of this vulnerability wishes to remain anonymous.
&lt;br&gt;&lt;br&gt;- fontdir CVE-2007-1352
&lt;br&gt;&lt;br&gt;fonts.dir File Parsing Integer Overflow Vulnerability
&lt;br&gt;&lt;br&gt;The discoverer of this vulnerability wishes to remain anonymous.
&lt;br&gt;&lt;br&gt;&lt;br&gt;- libX11 CVE-2007-1667
&lt;br&gt;&lt;br&gt;Multiple integer overflows in the XGetPixel() and XInitImage functions
&lt;br&gt;in ImUtil.c
&lt;br&gt;&lt;br&gt;&lt;br&gt;These vulnerabilities have been fixed in the OpenBSD CVS repository 
&lt;br&gt;in the -current and -stable branches. &amp;nbsp;The -current snapshots of X11
&lt;br&gt;contain these fixes as well.
&lt;br&gt;&lt;br&gt;It is recommended that users of X11 on OpenBSD update their X11
&lt;br&gt;installation using cvs or manually apply the source code patches listed
&lt;br&gt;below.
&lt;br&gt;&lt;br&gt;A source code patch for OpenBSD 4.0-stable can be downloaded from
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/011_xorg.patch.
&lt;br&gt;&lt;br&gt;A source code patch for OpenBSD 3.9-stable can be downloaded from
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/021_xorg.patch.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Multiple-vulnerabilities-in-X.Org-tp9840530p9840530.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-9533875</id>
	<title>OpenBSD SECURITY FIX: Incorrect mbuf handling for ICMP6 packets, 2nd revision</title>
	<published>2007-03-17T15:24:29Z</published>
	<updated>2007-03-17T15:24:29Z</updated>
	<author>
		<name>Henning Brauer-2</name>
	</author>
	<content type="html">A second revision of the patch fixing incorrect mbuf handling for ICMP6 
&lt;br&gt;packets has been created.
&lt;br&gt;&lt;br&gt;It will be available via ftp soon from the URLs given below.
&lt;br&gt;The fix has also been applied to the OpenBSD 3.9 and 4.0 stable branches 
&lt;br&gt;in cvs, please see &lt;a href=&quot;http://www.openbsd.org/stable.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openbsd.org/stable.html&lt;/a&gt;&amp;nbsp;for details.
&lt;br&gt;&lt;br&gt;Please make sure you get the second revision of the patch, as noted in 
&lt;br&gt;the patch files.
&lt;br&gt;&lt;br&gt;OpenBSD 3.9: errata 020
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/020_m_dup1.patch
&lt;br&gt;&lt;br&gt;OpenBSD 4.0: errata 010
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/010_m_dup1.patch
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenBSD-SECURITY-FIX%3A-Incorrect-mbuf-handling-for-ICMP6-packets%2C-2nd-revision-tp9533875p9533875.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8150049</id>
	<title>agp_ioctl() vulnerability fix</title>
	<published>2007-01-03T13:34:16Z</published>
	<updated>2007-01-03T13:34:16Z</updated>
	<author>
		<name>Miod Vallat (on the road)</name>
	</author>
	<content type="html">Insufficient validation in vga(4) may allow an attacker to gain root
&lt;br&gt;privileges if the kernel is compiled with option PCIAGP and the actual
&lt;br&gt;device is not an AGP device. The PCIAGP option is present by default on
&lt;br&gt;i386 kernels only. This vulnerability has been discovered by Ilja van
&lt;br&gt;Sprundel.
&lt;br&gt;&lt;br&gt;A patch addressing this problem is available in the -STABLE branches for
&lt;br&gt;OpenBSD 3.9 and OpenBSD 4.0. Standalone patch files are also available:
&lt;br&gt;&lt;br&gt;- for OpenBSD 4.0:
&lt;br&gt;&amp;nbsp; ftp://ftp.OpenBSD.org/pub/OpenBSD/patches/4.0/i386/007_agp.patch
&lt;br&gt;&lt;br&gt;- for OpenBSD 3.9:
&lt;br&gt;&amp;nbsp; ftp://ftp.OpenBSD.org/pub/OpenBSD/patches/3.9/i386/017_agp.patch
&lt;br&gt;&lt;br&gt;For more information about OpenBSD errata and how to apply them, please
&lt;br&gt;refer to FAQ 10.15: &lt;a href=&quot;http://www.OpenBSD.org/faq/faq10.html#Patches&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.OpenBSD.org/faq/faq10.html#Patches&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/agp_ioctl%28%29-vulnerability-fix-tp8150049p8150049.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-7481306</id>
	<title>The ELF ld.so(1) fails to properly sanitize the environment.</title>
	<published>2006-11-20T19:14:09Z</published>
	<updated>2006-11-20T19:14:09Z</updated>
	<author>
		<name>Brad-86</name>
	</author>
	<content type="html">The ELF ld.so(1) fails to properly sanitize the environment.
&lt;br&gt;There is a potential localhost security problem in cases we
&lt;br&gt;have not found yet. This patch applies to all ELF-based systems
&lt;br&gt;(m68k, m88k, and vax are a.out-based systems).
&lt;br&gt;&lt;br&gt;Patches for the respective releases:
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/005_ldso.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/016_ldso.patch
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/The-ELF-ld.so%281%29-fails-to-properly-sanitize-the-environment.-tp7481306p7481306.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-4934833</id>
	<title>potential denial of service problem in sendmail.</title>
	<published>2006-06-16T19:58:21Z</published>
	<updated>2006-06-16T19:58:21Z</updated>
	<author>
		<name>Brad-86</name>
	</author>
	<content type="html">A potential denial of service problem has been found in sendmail.
&lt;br&gt;A malformed MIME message could trigger excessive recursion which
&lt;br&gt;will lead to stack exhaustion. This denial of service attack only
&lt;br&gt;affects delivery of mail from the queue and delivery of a malformed
&lt;br&gt;message. Other incoming mail is still accepted and delivered.
&lt;br&gt;However, mail messages in the queue may not be reattempted if a
&lt;br&gt;malformed MIME message exists.
&lt;br&gt;&lt;br&gt;Patches for the respective releases:
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/003_sendmail2.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/008_sendmail2.patch
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/potential-denial-of-service-problem-in-sendmail.-tp4934833p4934833.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-4204890</id>
	<title>X.Org server security vulnerability</title>
	<published>2006-05-02T23:38:46Z</published>
	<updated>2006-05-02T23:38:46Z</updated>
	<author>
		<name>Peter Valchev-2</name>
	</author>
	<content type="html">A security vulnerability has been found in the X.Org server --
&lt;br&gt;CVE-2006-1526. Clients authorized to connect to the X server are able to
&lt;br&gt;crash it and to execute malicious code within the X server.
&lt;br&gt;&lt;br&gt;Patches for the respective releases:
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/002_xorg.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/007_xorg.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/013_xorg.patch
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/X.Org-server-security-vulnerability-tp4204890p4204890.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-3681305</id>
	<title>security hole in sendmail</title>
	<published>2006-03-30T16:08:11Z</published>
	<updated>2006-03-30T16:08:11Z</updated>
	<author>
		<name>Peter Valchev-2</name>
	</author>
	<content type="html">A race condition exists in sendmail's handling of asynchronous signals.
&lt;br&gt;A remote attacker may be able to execute arbitrary source code with the
&lt;br&gt;privileges of the user running sendmail, typically root.
&lt;br&gt;&lt;br&gt;The fixes have been applied to the 3.7-stable, 3.8-stable and 3.9-stable
&lt;br&gt;branches, and are also available as patches. &amp;nbsp;3.9-current has been
&lt;br&gt;updated to the new sendmail version which has this addressed as well.
&lt;br&gt;&lt;br&gt;Patches for the respective releases:
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/001_sendmail.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/006_sendmail.patch
&lt;br&gt;ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/012_sendmail.patch
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/security-hole-in-sendmail-tp3681305p3681305.html" />
</entry>

</feed>
