version 1.310, 2001/02/16 01:15:40 |
version 1.311, 2001/02/22 14:45:11 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=sudo></a> |
|
<li><font color=#009000><strong>020: SECURITY FIX: Feb 22, 2001</strong></font><br> |
|
There is a buffer overflow in |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sudo&sektion=8">sudo</a>. |
|
It is not currently known whether this is exploitable. |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/021_sudo.patch">A source code patch exists which remedies the problem.</a><br> |
|
<p> |
<a name=libwrap></a> |
<a name=libwrap></a> |
<li><font color=#009000><strong>020: IMPLEMENTATION FIX: Feb 15, 2001</strong></font><br> |
<li><font color=#009000><strong>020: IMPLEMENTATION FIX: Feb 15, 2001</strong></font><br> |
Client side ident protocol was broken in libwrap, affecting anything using libwrap including <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=tcpd&sektion=8">tcpd</a>. The effect of this was that libwrap would never retrieve and log ident values from remote hosts on connections. |
Client side ident protocol was broken in libwrap, affecting anything using libwrap including <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=tcpd&sektion=8">tcpd</a>. The effect of this was that libwrap would never retrieve and log ident values from remote hosts on connections. |