zlib patch available
"Todd C. Miller" <[email protected]>
| Newsgroups | gmane.openbsd.security.announce |
|---|---|
| Message-ID | <[email protected]> |
While we do not believe OpenBSD to be vulnerable to the recent
'double free' issue with zlib (the BSD malloc detects this condition)
patches are available for those who wish to update to zlib 1.1.4.
There is also a kernel zlib component that is used for kernel-based
PPP and IPSec in some cases. It is not known at this time whether
the zlib issue can be used to subvert the kernel zlib.
Patch for OpenBSD 3.0:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/015_zlib.patch
Patch for OpenBSD 2.9:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/022_zlib.patch
The 2.9 patch may also be used for OpenBSD 2.8.
The 2.9-stable and 3.0-stable branches (cvs tags OPENBSD_2_9 and
OPENBSD_3_0 respectively) also contain the updated zlib.
- todd