Return to errata.html CVS log | Up to [local] / www |
version 1.336, 2001/06/14 16:49:56 | version 1.337, 2001/06/15 16:45:26 | ||
---|---|---|---|
|
|
||
<a name=all></a> | <a name=all></a> | ||
<li><h3><font color=#e00000>All architectures</font></h3> | <li><h3><font color=#e00000>All architectures</font></h3> | ||
<ul> | <ul> | ||
<a name=kernexec></a> | |||
<li><font color=#009000><strong>007: SECURITY FIX: June 15, 2001</strong></font><br> | |||
A race condition exists in the kernel <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=execve&sektion=2&format=html">execve(2)</a> implementation that opens a small window of vulnerability for a non-privileged user to <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ptrace&sektion=2&format=html">ptrace(2)</a> attach to a suid/sgid process. | |||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/007_kernexec.patch">A source code patch exists which remedies the problem</a>. | |||
<p> | |||
<a name=sshcookie></a> | <a name=sshcookie></a> | ||
<li><font color=#009000><strong>006: SECURITY FIX: June 12, 2001</strong></font><br> | <li><font color=#009000><strong>006: SECURITY FIX: June 12, 2001</strong></font><br> | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sshd&sektion=8&format=html">sshd(8)</a> | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sshd&sektion=8&format=html">sshd(8)</a> |