• [^] # Re: Faille de sécurité critique dans le kernel (2.2, 2.4, 2.6 touché!)

    Posté par . En réponse au journal Faille de sécurité critique dans le kernel (2.2, 2.4, 2.6 touché!). Évalué à 2.

    OpenBSD 3.4 Security Advisories
    These are the OpenBSD 3.4 advisories -- all these problems are solved in OpenBSD current and the patch branch.

    * February 8, 2004: An IPv6 MTU handling problem exists that could be used by an attacker to cause a denial of service attack.
    * February 5, 2004: A reference counting bug in shmat(2) could be used to write to kernel memory under certain circumstances.
    * January 13, 2004: Several message handling flaws in isakmpd(8) have been reported by Thomas Walpuski.
    * November 17, 2003: It may be possible for a local user to overrun the stack in compat_ibcs2(8) and cause a kernel panic.
    * November 1, 2003: The use of certain ASN.1 encodings or malformed public keys may allow an attacker to mount a denial of service attack against applications linked with ssl(3).