version 1.361, 2001/11/14 01:38:00 |
version 1.362, 2001/12/04 02:53:13 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=lpd> |
|
<li><font color=#009000><strong>007: SECURITY FIX: November 28, 2001</strong></font><br> |
|
A security issue exists in the lpd daemon that may allow an attacker |
|
to create arbitrary new files in the root directory. Only machines |
|
with line printer access (ie: listed in either /etc/hosts.lpd or |
|
/etc/hosts.equiv) may be used to mount an attack and the attacker |
|
must have root access on the machine. OpenBSD does not start lpd |
|
in the default installation. |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/008_lpd.patch">A source code patch exists which remedies the problem</a>. |
|
<p> |
<a name=vi.recover> |
<a name=vi.recover> |
<li><font color=#009000><strong>007: SECURITY FIX: November 13, 2001</strong></font><br> |
<li><font color=#009000><strong>007: SECURITY FIX: November 13, 2001</strong></font><br> |
A security issue exists in the vi.recover script that may allow an attacker |
A security issue exists in the vi.recover script that may allow an attacker |