[BACK]Return to errata.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata.html between version 1.285 and 1.286

version 1.285, 2000/12/05 17:11:37 version 1.286, 2000/12/08 04:01:23
Line 45 
Line 45 
 <a name=all></a>  <a name=all></a>
 <li><h3><font color=#e00000>All architectures</font></h3>  <li><h3><font color=#e00000>All architectures</font></h3>
 <ul>  <ul>
   <a name=kerberos></a>
   <li><font color=#009000><strong>006: SECURITY FIX: Dec 7, 2000</strong></font><br>
   Two problems have recently been discovered in the KerberosIV code.<p>
   1. A symlink problem was discovered in the KerberosIV password checking
   routines /usr/bin/su and /usr/bin/login, which makes it possible for a
   local user to overwrite any file on the local machine.<p>
   2. It is possible to specify to specify environment variables in telnet
   which will be passed over the to the remote host. This makes it
   possible to set environment variables on the remote side, including
   ones that have special meaning on the server. It is not clear at this
   time what the impact is, but we recommend everyone to upgrade their
   machines immediatly.<p>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/006_kerberos.patch">
   A source code patch exists which remedies the problem.</a>
   <p>
 <a name=ftpd></a>  <a name=ftpd></a>
 <li><font color=#009000><strong>005: SECURITY FIX: Dec 4, 2000</strong></font><br>  <li><font color=#009000><strong>005: SECURITY FIX: Dec 4, 2000</strong></font><br>
 OpenBSD 2.8's ftpd contains a one-byte overflow in the replydirname() function.<br>  OpenBSD 2.8's ftpd contains a one-byte overflow in the replydirname() function.<br>

Legend:
Removed from v.1.285  
changed lines
  Added in v.1.286