Return to errata.html CVS log | Up to [local] / www |
version 1.389, 2002/04/25 16:13:37 | version 1.390, 2002/04/25 16:39:30 | ||
---|---|---|---|
|
|
||
<ul> | <ul> | ||
<a name=sudo></a> | <a name=sudo></a> | ||
<li><font color=#009000><strong>002: SECURITY FIX: April 25, 2002</strong></font><br> | <li><font color=#009000><strong>002: SECURITY FIX: April 25, 2002</strong></font><br> | ||
A bug in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sudo&sektion=8">sudo(8)</a> may allow an attacker to corrupt the heap by specifying a custom prompt. | A bug in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sudo&sektion=8">sudo(8)</a> may allow an attacker to corrupt the heap by specifying a custom prompt.<br> | ||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/002_sudo.patch">A source code patch exists which remedies the problem</a>. | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.1/common/002_sudo.patch">A source code patch exists which remedies the problem</a>. | ||
<p> | <p> | ||
<a name=sshafs></a> | <a name=sshafs></a> |