version 1.369, 2002/01/19 21:17:42 |
version 1.370, 2002/01/21 18:25:59 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<li><font color=#009000><strong>012: SECURITY FIX: January 21, 2002</strong></font><br> |
|
<a name=ptrace></a> |
|
A race condition between the ptrace(2) and execve(2) system calls allows |
|
an attacker to modify the memory contents of suid/sgid processes which |
|
could lead to compromise of the super-user account.<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/012_ptrace.patch">A source code patch exists which remedies the problem</a>. |
|
<p> |
<a name=sudo> |
<a name=sudo> |
<li><font color=#009000><strong>011: SECURITY FIX: January 17, 2002</strong></font><br> |
<li><font color=#009000><strong>011: SECURITY FIX: January 17, 2002</strong></font><br> |
If the Postfix sendmail replacement is installed on a system an |
If the Postfix sendmail replacement is installed on a system an |