Return to errata.html CVS log | Up to [local] / www |
version 1.350, 2001/08/21 17:54:38 | version 1.351, 2001/08/23 06:00:16 | ||
---|---|---|---|
|
|
||
A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sendmail&sektion=8">sendmail(8)</a> | A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sendmail&sektion=8">sendmail(8)</a> | ||
that may allow an attacker on the local host to gain root privileges by | that may allow an attacker on the local host to gain root privileges by | ||
specifying out-of-bounds debug parameters. | specifying out-of-bounds debug parameters. | ||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/013_sendmail.patch">A source code patch exists which remedies the problem</a> | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/013_sendmail.patch">A source code patch exists which remedies the problem</a> | ||
<p> | <p> | ||
<a name=nfs> | <a name=nfs> | ||
|
|
||
only users with <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=mount&sektion=2">mount(2)</a> | only users with <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=mount&sektion=2">mount(2)</a> | ||
privileges can initiate this attack. In default installs, only super-user has | privileges can initiate this attack. In default installs, only super-user has | ||
mount privileges. The kern.usermount <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sysctl&sektion=3">sysctl(3)</a> controls whether other users have mount privileges. | mount privileges. The kern.usermount <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sysctl&sektion=3">sysctl(3)</a> controls whether other users have mount privileges. | ||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/012_nfs.patch">A source code patch exists which remedies the problem</a> | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/012_nfs.patch">A source code patch exists which remedies the problem</a> | ||
<p> | <p> | ||
<a name=pkg></a> | <a name=pkg></a> |