version 1.139, 1998/07/28 20:27:17 |
version 1.140, 1998/08/02 03:55:20 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=chpass></a> |
|
<li><font color=#009000><strong>SECURITY FIX</strong></font><br> |
|
Chpass(1) has a file descriptor leak which allows an |
|
attacker to modify /etc/master.passwd. |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.3/common/chpass.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
<a name=resid></a> |
<a name=resid></a> |
<li><font color=#009000><strong>RELIABILITY FIX</strong></font><br> |
<li><font color=#009000><strong>RELIABILITY FIX</strong></font><br> |
Calling readv(2) with iov_len < 0 or > INT_MAX would result in a |
Calling readv(2) with iov_len < 0 or > INT_MAX would result in a |