version 1.325, 2001/05/24 07:03:09 |
version 1.326, 2001/05/30 03:32:16 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
<li>No problems identified yet. |
<a name=sendmail></a> |
|
<li><font color=#009000><strong>001: SECURITY FIX: May 29, 2001</strong></font><br> |
|
The signal handlers in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sendmail&sektion=8&format=html">sendmail(8)</a> contain code that is unsafe in the |
|
context of a signal handler. This leads to potentially serious |
|
race conditions. At the moment this is a theoretical attack only |
|
and can only be exploited on the local host (if at all).<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/001_sendmail.patch">A source code patch exists</a> which remedies the problem by updating sendmail to version 8.11.4.<br> |
</ul> |
</ul> |
<p> |
<p> |
<a name=i386></a> |
<a name=i386></a> |