First: the securityfocus links in the references section are dead.
Also, I dont believe that OpenBSDD was vulnerable in this instance. In fact, Theo argues that Joost may have found this vulnerability when he stumbled across OpenBSDs 1998 fix for it: <http://archives.neohapsis.com/archives/bugtraq/2002-04/0304.html>
However, on May 9 there was a problem found with OpenBSDs fix: <http://archives.neohapsis.com/archives/bugtraq/2002-05/0066.html>
You have the vulns noted on May 9 as separate vulnerabilities: OSVDB 5114 and 5715. I think they are, indeed, separate.
So, I think OpenBSD might ought be removed from this entry. Im not sure, but I thought Id share my thoughts with you!
Cheers, Andy
|