[BACK]Return to errata.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata.html between version 1.442 and 1.443

version 1.442, 2003/05/08 08:38:20 version 1.443, 2003/08/04 16:39:29
Line 54 
Line 54 
 <a name=all></a>  <a name=all></a>
 <li><h3><font color="#e00000">All architectures</font></h3>  <li><h3><font color="#e00000">All architectures</font></h3>
 <ul>  <ul>
 <li>No problems identified yet.  <a name=realpath></a>
   <li><font color="#009000"><strong>001: SECURITY FIX: August 4, 2003</strong></font><br>
   An off-by-one error exists in the C library function
   <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=realpath&amp;sektion=3">realpath(3)</a>.
   Since this same bug resulted in a root compromise in the wu-ftpd ftp server
   it is possible that this bug may allow an attacker to gain escalated privileges
   on OpenBSD.<br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/001_realpath.patch">A
   source code patch exists which remedies the problem</a>.
   <p>
 </ul>  </ul>
 <p>  <p>
 <a name=i386></a>  <a name=i386></a>

Legend:
Removed from v.1.442  
changed lines
  Added in v.1.443