version 1.254, 2000/07/05 04:15:26 |
version 1.255, 2000/07/05 22:40:38 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=ftpd></a> |
|
<li><font color=#009000><strong>019: SECURITY FIX: July 5, 2000</strong></font><br> |
|
Just like pretty much all the other unix ftp daemons on the planet, |
|
ftpd had a remote root hole in it. Luckily, ftpd was not enabled by default. |
|
The problem exists if anonymous ftp is enabled, or if a hostile user has a |
|
valid login. |
|
<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/019_ftpd.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
|
<a name=mopd></a> |
|
<li><font color=#009000><strong>018: SECURITY FIX: July 5, 2000</strong></font><br> |
|
Mopd contained a buffer overflow. |
|
<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/018_mopd.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
<a name=screen></a> |
<a name=screen></a> |
<li><font color=#009000><strong>017: INSTALLATION FIX: July 3, 2000</strong></font> |
<li><font color=#009000><strong>017: INSTALLATION FIX: July 3, 2000</strong></font> |
<br> |
<br> |