006: SECURITY FIX: June 24, 2002 An (as yet) undisclosed bug exists in OpenSSH which a patch is not forthcoming for yet -- no patch exists yet! However, upgrading to OpenSSH 3.3 with the UsePrivilegeSeparation option enabled will block this problem. All users are advised to update immediately, and keep an eye out for a upcoming OpenSSH 3.4 release on Monday containing a real fix.
008: SECURITY FIX: June 26, 2002 A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd module, leading to possible remote crash or exploit.
013: SECURITY FIX: July 30, 2002 Several remote buffer overflows can occur in the SSL2 server and SSL3 client of the ssl(8) library, as in the ASN.1 parser code in the crypto(3) library, all of them being potentially remotely exploitable.
012: SECURITY FIX: July 29, 2002 A buffer overflow can occur in the xdr_array(3) RPC code, leading to possible remote crash.
011: SECURITY FIX: July 29, 2002 A race condition exists in the pppd(8) daemon which may cause it to alter the file permissions of an arbitrary file.
CD boot: Booting off the CD provides an El Torito 2.88MB floppy image that contains almost all OpenBSD drivers. This also includes minimal USB support (umass and ukbd devices). <-ここ For the latest list of drivers available on this image, take a look at the RAMDISK_CD config file.