<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
  <channel>
    <title>OpenBSD 43 Errata</title>
    <link>http://www.openbsd.org/errata43.html</link>
    <description>OpenBSD 43 Errata</description>
    <language>en-us</language>
    <managingEditor>mike@erdelynet.com</managingEditor>

    <image>
      <title>erdelynet.com</title>
      <url>http://erdelynet.com/images/puffy96x83.gif</url>
      <link>http://www.openbsd.org/errata43.html</link>
      <width>96</width>
      <height>83</height>
      <description>OpenBSD 43 Errata</description>
    </image>

    <item>
      <title>005 RELIABILITY 005_pcb</title>
      <link>http://www.openbsd.org/errata43.html#005_pcb</link>
      <category>RELIABILITY</category>
      <architecture>All architectures</architecture>
      <pubDate>July 29, 2008</pubDate>
      <description><![CDATA[
 Some kinds of IPv6 usage would leak kernel memory (in particular, this path  was exercised by the named(8) patch for port randomization).  Since INET6 is  enabled by default, this condition affects all systems. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/005_pcb.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>004 SECURITY 004_bind</title>
      <link>http://www.openbsd.org/errata43.html#004_bind</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>July 23, 2008</pubDate>
      <description><![CDATA[
 <strong>2nd revision, July 23, 2008</strong><br> A vulnerability has been found with BIND. An attacker could use this vulnerability to poison the cache of a recursive resolving name server. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447">CVE-2008-1447</a>. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/004_bind.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>003 SECURITY 003_xorg</title>
      <link>http://www.openbsd.org/errata43.html#003_xorg</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>July 15, 2008</pubDate>
      <description><![CDATA[
 Multiple vulnerabilities have been discovered in X.Org.<br> RENDER Extension heap buffer overflow, RENDER Extension crash, RENDER Extension memory corruption, MIT-SHM arbitrary memory read, RECORD and Security extensions memory corruption. <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2360">CVE-2008-2360</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2361">CVE-2008-2361</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2362">CVE-2008-2362</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1379">CVE-2008-1379</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1377">CVE-2008-1377</a>. <br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/003_xorg.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>002 SECURITY 002_openssh2</title>
      <link>http://www.openbsd.org/errata43.html#002_openssh2</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>April 3, 2008</pubDate>
      <description><![CDATA[
 Avoid possible hijacking of X11-forwarded connections with sshd(8) by refusing to listen on a port unless all address families bind successfully.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/002_openssh2.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

    <item>
      <title>001 SECURITY 001_openssh</title>
      <link>http://www.openbsd.org/errata43.html#001_openssh</link>
      <category>SECURITY</category>
      <architecture>All architectures</architecture>
      <pubDate>March 30, 2008</pubDate>
      <description><![CDATA[
 sshd(8) would execute ~/.ssh/rc even when a sshd_config(5) <em>ForceCommand</em> directive was in effect, allowing users with write access to this file to execute arbitrary commands. This behaviour was documented, but was an unsafe default and an extra hassle for administrators.<br> <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/001_openssh.patch"> A source code patch exists which remedies this problem</a>.<br>
]]></description>
    </item>

  </channel>
</rss>
