version 1.219, 2000/01/09 10:25:59 |
version 1.220, 2000/01/20 17:49:32 |
|
|
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
<a name=aty2k></a> |
<a name=aty2k></a> |
|
<li><font color=#009000><strong>016: SECURITY FIX: Jan 20, 2000</strong></font><br> |
|
Systems running with procfs enabled and mounted are vulnerable |
|
to having the stderr output of setuid processes directed onto |
|
a pre-seeked descriptor onto the stack in their own procfs memory.<br> |
|
Note that procfs is not mounted by default in OpenBSD.<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/016_procfs.patch> |
|
A source code patch exists, which remedies this problem.</a> |
|
<p> |
|
<a name=aty2k></a> |
<li><font color=#009000><strong>015: Y2K FIX: Jan 9, 2000</strong></font><br> |
<li><font color=#009000><strong>015: Y2K FIX: Jan 9, 2000</strong></font><br> |
The at(1) command was unable to parse some kinds of dates.<br> |
The at(1) command was unable to parse some kinds of dates.<br> |
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/015_aty2k.patch> |
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.6/common/015_aty2k.patch> |