===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.538
retrieving revision 1.539
diff -c -r1.538 -r1.539
*** www/errata.html 2005/06/16 02:42:45 1.538
--- www/errata.html 2005/06/21 04:04:27 1.539
***************
*** 73,78 ****
--- 73,90 ----
+ -
+ 003: SECURITY FIX: June 20, 2005 All architectures
+ Due to a race condition in its command pathname handling, a user with
+ sudo(8)
+ privileges may be able to run arbitrary commands if the user's entry
+ is followed by an entry that grants sudo ALL privileges to
+ another user.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
002: RELIABILITY FIX: June 15, 2005 All architectures
As discovered by Stefan Miltchev calling
***************
*** 127,133 ****
www@openbsd.org
!
$OpenBSD: errata.html,v 1.538 2005/06/16 02:42:45 brad Exp $