A second remote hole for OpenBSD
[Posted March 14, 2007 by corbet]
Visitors to the
OpenBSD site will notice
that it now reads "Only two remote holes in the default install, in more
than 10 years!" That's one more than it had a little while ago. The
details can be found in
this Core Security
advisory: it seems that the problem was in the IPv6 code. It's amusing
to read the timeline - the OpenBSD folks were apparently not enthusiastic
about accepting the existence of a remotely exploitable vulnerability.
They did accept it, though, and their record over many years remains
impressive.
(
Log in to post comments)