SEMI OFF-TOPIC

Jorge Severino jorge en netsecure.cl
Mar Nov 5 13:08:42 CLST 2002


el problema es que en openbsd las librerias estan estaticamente linkeadas,
en cambio en el apache para el linux no....ahi radica el principio del
problema---



                        SuSE Security Announcement

        Package:                openssl/Slapper worm
        Announcement-ID:        SuSE-SA:2002:033
        Date:                   Thu Sep 19 2002
        Affected products:      7.0, 7.1, 7.2, 7.3, 8.0
                                SuSE Linux Database Server,
                                SuSE eMail Server III,
                                SuSE eMail Server 3.1,
                                SuSE Linux Enterprise Server,
                                SuSE Linux Firewall on CD,
                                SuSE Linux Enterprise Server 7
                                SuSE Linux Office Server
        Vulnerability Type:     buffer overflow
        Severity (1-10):        9
        SuSE default package:   yes
        Cross References:       CVE CAN-2002-0655, CAN-2002-0656,
                                CAN-2002-0659, SuSE-SA:2002:027

    Content of this advisory:
        1) vulnerabilities in openssl libraries; Slapper worm
        2) pending vulnerabilities, solutions, workarounds
        3) standard appendix (further information)