===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.186
retrieving revision 1.187
diff -c -r1.186 -r1.187
*** www/errata.html 1999/07/18 02:27:07 1.186
--- www/errata.html 1999/07/30 21:23:52 1.187
***************
*** 35,40 ****
--- 35,56 ----
All architectures
+
+ - SECURITY FIX
+ Do not permit regular users to chflags(2) or fchflags(2) on character or
+ block devices which they may currently be the owner of.
+
+ A source code patch exists which remedies this problem.
+
+
+
- SECURITY FIX
+ Cause groff(1) to be invoked with the -S flag, when called by nroff(1),
+ to avoid various groff features which may be security issues. On the
+ whole, this is not really a security issue, but it was discussed on
+ BUGTRAQ as if it is.
+
+ A source code patch exists which remedies this problem.
+
- RELIABILITY FIX
Programs using fts(3) could dump core when given a directory structure
***************
*** 159,165 ****
www@openbsd.org
!
$OpenBSD: errata.html,v 1.186 1999/07/18 02:27:07 deraadt Exp $