Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 19 Mar 2002 23:16:59 +0200
From:      Dmitry Pryanishnikov <dmitry@atlantis.dp.ua>
Subject:   HEADS UP: FreeBSD-SA-02:18.zlib vs kern/35969
Message-ID:  <Pine.BSF.4.31.0203192307200.33201-100000@atlantis.dp.ua>
In-Reply-To: <200203181500.g2IF04C32485@freefall.freebsd.org.lucky.freebsd.security>
References:  <200203181500.g2IF04C32485@freefall.freebsd.org.lucky.freebsd.security>

next in thread | previous in thread | raw e-mail | index | archive | help

Hello!

  Heads up! The fix given with this advisory seems to be buggy, at least in
kernel part (sys/net/zlib.c, see kern/35969). Now, while PR is still open,
what would be wise: use patched or non-patched kernel? Patched one could panic
with PPP_DEFLATE - what could be done with non-patched one by hackers?
Also, has fix for lib/libz/infblock.c been verified for correctness?


Sincerely, Dmitry

Atlantis ISP, System Administrator
e-mail:  dmitry@atlantis.dp.ua
nic-hdl: LYNX-RIPE



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.31.0203192307200.33201-100000>