Return to errata.html CVS log | Up to [local] / www |
version 1.578, 2006/11/20 01:35:19 | version 1.579, 2006/11/20 08:27:20 | ||
---|---|---|---|
|
|
||
<li><a name="ldso"></a> | <li><a name="ldso"></a> | ||
<font color="#009000"><strong>005: SECURITY FIX: November 19, 2006</strong></font> <i>All architectures</i><br> | <font color="#009000"><strong>005: SECURITY FIX: November 19, 2006</strong></font> <i>All architectures</i><br> | ||
The ELF | |||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ld.so&sektion=1">ld.so(1)</a> | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ld.so&sektion=1">ld.so(1)</a> | ||
fails to properly sanitize the environment. There is a potential localhost security | fails to properly sanitize the environment. There is a potential localhost security | ||
problem in cases we have not found yet. | problem in cases we have not found yet. This patch applies to all ELF-based | ||
systems (m68k, m88k, and vax are a.out-based systems). | |||
<br> | <br> | ||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/005_ldso.patch"> | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/005_ldso.patch"> | ||
A source code patch exists which remedies this problem</a>.<br> | A source code patch exists which remedies this problem</a>.<br> |