version 1.249, 2000/06/25 08:41:36 |
version 1.250, 2000/06/28 18:10:01 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=libedit></a> |
|
<li><font color=#009000><strong>013: SECURITY FIX: June 28, 2000</strong></font><br> |
|
libedit would check for a <b>.editrc</b> file in the current directory. |
|
That behaviour is not nice; this does not turn into a security problem in |
|
any real world situation that we know of, but a patch is available anyways. |
|
<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/013_libedit.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
<a name=dhclient></a> |
<a name=dhclient></a> |
<li><font color=#009000><strong>012: SECURITY FIX: June 24, 2000</strong></font><br> |
<li><font color=#009000><strong>012: SECURITY FIX: June 24, 2000</strong></font><br> |
A serious bug in dhclient(8) could allow strings from a malicious dhcp |
A serious bug in dhclient(8) could allow strings from a malicious dhcp |