CVE-2018-6532: By sending specially crafted requests, authenticated and unauthenticated, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer. CVE-2018-6534: By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause Icinga2 to crash. CVE-2018-6535: Lack of a constant-time password comparison function can disclose the password to an attacker. Detailed write-up and simple crashers for the above at https://hansmi.ch/articles/2018-03-icinga2-security (CVE-2017-16933 and CVE-2018-6536 also in this release relate to the init scripts that we don't use).
Documentation for the ports tree: ports(7), packages(7), mirroring-ports(7), library-specs(7), bsd.port.mk(5), bsd.port.arch.mk(5), port-modules(5). dpb(1), bulk(8) (manpages under ${PORTSDIR}/infrastructure/man) for bulk builds. See also the OpenBSD Porter's Handbook http://www.openbsd.org/faq/ports/ $OpenBSD: README,v 1.22 2016/10/17 16:26:52 danj Exp $
Description
Public git conversion mirror of OpenBSD's official cvs ports repository. Pull requests not accepted - send diffs to the ports@ mailing list.
Languages
Makefile
61%
PHP
18.9%
Perl
6.5%
C
4.6%
HTML
2.3%
Other
6.4%