Return to errata27.html CVS log | Up to [local] / www |
version 1.14, 2001/03/18 20:32:44 | version 1.15, 2001/03/19 16:38:22 | ||
---|---|---|---|
|
|
||
in applications that use passwords and the like during user interaction | in applications that use passwords and the like during user interaction | ||
(one such application is mysql). Additionally, if the HOME environment | (one such application is mysql). Additionally, if the HOME environment | ||
variable is not set, the current working directory is used; this patch | variable is not set, the current working directory is used; this patch | ||
disables the history file if HOME is not set. | disables the history file if HOME is not set.<br> | ||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/040_readline.patch | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/040_readline.patch | ||
">A source code patch exists which remedies the problem.</a><br> | ">A source code patch exists which remedies the problem.</a><br> | ||
<p> | <p> | ||
|
|
||
<li><font color=#009000><strong>039: SECURITY FIX: Feb 22, 2001</strong></font><br> | <li><font color=#009000><strong>039: SECURITY FIX: Feb 22, 2001</strong></font><br> | ||
There is a buffer overflow in | There is a buffer overflow in | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sudo&sektion=8">sudo</a>. | <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sudo&sektion=8">sudo</a>. | ||
It is not currently known whether this is exploitable. | It is not currently known whether this is exploitable.<br> | ||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/039_sudo.patch">A | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/039_sudo.patch">A | ||
source code patch exists which remedies the problem.</a><br> | source code patch exists which remedies the problem.</a><br> | ||
<p> | <p> |