version 1.275, 2000/10/10 00:02:44 |
version 1.276, 2000/10/10 18:10:46 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=telnetd></a> |
|
<li><font color=#009000><strong>029: SECURITY FIX: Oct 10, 2000</strong></font><br> |
|
The telnet daemon does not strip out the TERMINFO, TERMINFO_DIRS, TERMPATH |
|
and TERMCAP (when it starts with a '/') environment variables. |
|
<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/030_telnetd.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
<a name=sendmail></a> |
<a name=sendmail></a> |
<li><font color=#009000><strong>029: RELIABILITY FIX: Oct 9, 2000</strong></font><br> |
<li><font color=#009000><strong>029: RELIABILITY FIX: Oct 9, 2000</strong></font><br> |
There is a non-exploitable buffer overflow in sendmail's test mode. |
There is a non-exploitable buffer overflow in sendmail's test mode. |