[BACK]Return to errata.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata.html between version 1.278 and 1.279

version 1.278, 2000/10/11 02:10:22 version 1.279, 2000/10/18 20:39:24
Line 44 
Line 44 
 <a name=all></a>  <a name=all></a>
 <li><h3><font color=#e00000>All architectures</font></h3>  <li><h3><font color=#e00000>All architectures</font></h3>
 <ul>  <ul>
   <a name=httpd></a>
   <li><font color=#009000><strong>031: SECURITY FIX: Oct 18, 2000</strong></font><br>
   Apache has several bugs in <tt>mod_rewrite</tt> and <tt>mod_vhost_alias</tt>
   that could cause arbirtary files accessible to the www user on the server
   to be exposed under certain configurations when these modules are used.
   (These modules are not active by default).
   <br>
   <a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/031_httpd.patch>
   A source code patch exists which remedies this problem.</a>
   <p>
 <a name=telnetd></a>  <a name=telnetd></a>
 <li><font color=#009000><strong>030: SECURITY FIX: Oct 10, 2000</strong></font><br>  <li><font color=#009000><strong>030: SECURITY FIX: Oct 10, 2000</strong></font><br>
 The telnet daemon does not strip out the TERMINFO, TERMINFO_DIRS, TERMPATH  The telnet daemon does not strip out the TERMINFO, TERMINFO_DIRS, TERMPATH

Legend:
Removed from v.1.278  
changed lines
  Added in v.1.279