[BACK]Return to errata.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata.html between version 1.353 and 1.354

version 1.353, 2001/08/29 22:25:27 version 1.354, 2001/09/12 13:52:39
Line 46 
Line 46 
 <a name=all></a>  <a name=all></a>
 <li><h3><font color=#e00000>All architectures</font></h3>  <li><h3><font color=#e00000>All architectures</font></h3>
 <ul>  <ul>
   <a name=uucp>
   <li><font color=#009000><strong>015: SECURITY FIX: September 11, 2001</strong></font><br>
   A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=uuxqt&sektion=8">uuxqt(8)</a>
   that may allow an attacker to run arbitrary commands as user uucp and
   use this to gain root access.
   The UUCP execution daemon, uuxqt(8), has a bug in its command line
   parsing routine that may allow arbitrary commands to be run.  Because
   some UUCP commands are run as root (and daemon) from cron it is possible
   to leverage compromise of the UUCP user to gain root.
   <br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/015_uucp.patch">A source code patch exists which remedies the problem</a>
   <p>
 <a name=lpd>  <a name=lpd>
 <li><font color=#009000><strong>014: SECURITY FIX: August 29, 2001</strong></font><br>  <li><font color=#009000><strong>014: SECURITY FIX: August 29, 2001</strong></font><br>
 A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lpd&sektion=8">lpd(8)</a>  A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lpd&sektion=8">lpd(8)</a>

Legend:
Removed from v.1.353  
changed lines
  Added in v.1.354