version 1.391, 2002/05/08 23:02:53 |
version 1.392, 2002/05/09 14:40:41 |
|
|
<li><font color=#009000><strong>003: SECURITY FIX: May 8, 2002</strong></font><br> |
<li><font color=#009000><strong>003: SECURITY FIX: May 8, 2002</strong></font><br> |
A race condition exists where an attacker could fill the file descriptor |
A race condition exists where an attacker could fill the file descriptor |
table and defeat the kernel's protection of fd slots 0, 1, and 2 for a |
table and defeat the kernel's protection of fd slots 0, 1, and 2 for a |
setuid or setgid process. |
setuid or setgid process.<br> |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/003_fdalloc2.patch">A source code patch exists which remedies the problem</a>. |
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/003_fdalloc2.patch">A source code patch exists which remedies the problem</a>. |
<p> |
<p> |
<a name=sudo></a> |
<a name=sudo></a> |