OpenBSD Halts Port to Pegasos

"At this point, I would recommend against anyone buying a piece of hardware from the Pegasos people because their firmware is SO BUSTED that it makes Apple roms look like hot sh**"." These are the words of the infamous Theo de Raadt, the OpenBSD founder. Theo cited problems with the BIOS of the Pegasos and other difficulties during the development of the OpenBSD port to the Pegasos platform.

OpenBSD 3.4 Released

The OpenBSD folks are pleased to announce the official release of OpenBSD 3.4. This is their 14th release on CD-ROM (and 15th via FTP). They remain proud of OpenBSD's record of seven years with only a single remote hole in the default install. As with previous releases, 3.4 provides significant improvements, including new features, in nearly all areas of the system:

MirBSD No7 Released

MirBSD is a derivative of OpenBSD. It is i386-only, and has some packages removed (Kerberos etc.). Additional features include IPv6 support in Apache, ports for djb-ware, a new bootloader and more.

OpenBSD: improper kernel bounds check; OS Fingerprinting in Firewall

OpenBSD's Todd Miller reports that an improper bounds check in the semget(2) system call can allow a local user to cause a kernel panic. No privilege escalation is possible, the attack simply runs the kernel out of memory. The bug was introduced in OpenBSD 3.3, previous versions of OpenBSD are unaffected. Earlier, Mike Frantzen has committed "Passive operating system fingerprinting" to PF which exposes the source host's OS to the filter language.