=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v retrieving revision 1.285 retrieving revision 1.286 diff -c -r1.285 -r1.286 *** www/errata.html 2000/12/05 17:11:37 1.285 --- www/errata.html 2000/12/08 04:01:23 1.286 *************** *** 45,50 **** --- 45,65 ----
+ 1. A symlink problem was discovered in the KerberosIV password checking + routines /usr/bin/su and /usr/bin/login, which makes it possible for a + local user to overwrite any file on the local machine.
+ 2. It is possible to specify to specify environment variables in telnet + which will be passed over the to the remote host. This makes it + possible to set environment variables on the remote side, including + ones that have special meaning on the server. It is not clear at this + time what the impact is, but we recommend everyone to upgrade their + machines immediatly.
+ + A source code patch exists which remedies the problem. +