version 1.387, 2002/04/17 13:16:49 |
version 1.388, 2002/04/23 20:52:51 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
<li>No problems identified yet. |
<a name=sshafs></a> |
|
<li><font color=#009000><strong>001: SECURITY FIX: April 22, 2002</strong></font><br> |
|
A local user can gain super-user privileges due to a buffer overflow |
|
in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sshd&sektion=8">sshd(8)</a> |
|
if AFS has been configured on the system or if |
|
KerberosTgtPassing or AFSTokenPassing has been enabled |
|
in the sshd_config file. Ticket and token passing is not enabled |
|
by default.<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/001_sshafs.patch">A source code patch exists which remedies the problem</a>. |
|
<p> |
</ul> |
</ul> |
<p> |
<p> |
<a name=i386></a> |
<a name=i386></a> |