version 1.278, 2000/10/11 02:10:22 |
version 1.279, 2000/10/18 20:39:24 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=httpd></a> |
|
<li><font color=#009000><strong>031: SECURITY FIX: Oct 18, 2000</strong></font><br> |
|
Apache has several bugs in <tt>mod_rewrite</tt> and <tt>mod_vhost_alias</tt> |
|
that could cause arbirtary files accessible to the www user on the server |
|
to be exposed under certain configurations when these modules are used. |
|
(These modules are not active by default). |
|
<br> |
|
<a href=ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/031_httpd.patch> |
|
A source code patch exists which remedies this problem.</a> |
|
<p> |
<a name=telnetd></a> |
<a name=telnetd></a> |
<li><font color=#009000><strong>030: SECURITY FIX: Oct 10, 2000</strong></font><br> |
<li><font color=#009000><strong>030: SECURITY FIX: Oct 10, 2000</strong></font><br> |
The telnet daemon does not strip out the TERMINFO, TERMINFO_DIRS, TERMPATH |
The telnet daemon does not strip out the TERMINFO, TERMINFO_DIRS, TERMPATH |