=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata22.html,v retrieving revision 1.25 retrieving revision 1.26 diff -c -r1.25 -r1.26 *** www/errata22.html 2001/06/09 16:39:02 1.25 --- www/errata22.html 2001/08/08 21:06:32 1.26 *************** *** 113,119 ****
  • SECURITY FIX
    A combination localhost+remote host security problem exists if a ! local user running a setuid binary causes a non-existant root .rhosts file to be created via a symbolic link with a specific kind of corefile, and then subsequently uses rsh/rlogin to enter the machine from remote. A similar exploit might also be possible using sshd which lacks any code --- 113,119 ----
  • SECURITY FIX
    A combination localhost+remote host security problem exists if a ! local user running a setuid binary causes a non-existent root .rhosts file to be created via a symbolic link with a specific kind of corefile, and then subsequently uses rsh/rlogin to enter the machine from remote. A similar exploit might also be possible using sshd which lacks any code *************** *** 183,189 ****