=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata22.html,v retrieving revision 1.25 retrieving revision 1.26 diff -u -r1.25 -r1.26 --- www/errata22.html 2001/06/09 16:39:02 1.25 +++ www/errata22.html 2001/08/08 21:06:32 1.26 @@ -113,7 +113,7 @@
  • SECURITY FIX
    A combination localhost+remote host security problem exists if a -local user running a setuid binary causes a non-existant root .rhosts +local user running a setuid binary causes a non-existent root .rhosts file to be created via a symbolic link with a specific kind of corefile, and then subsequently uses rsh/rlogin to enter the machine from remote. A similar exploit might also be possible using sshd which lacks any code @@ -183,7 +183,7 @@