Return to errata27.html CVS log | Up to [local] / www |
version 1.19, 2001/06/02 02:55:57 | version 1.20, 2001/06/07 02:06:39 | ||
---|---|---|---|
|
|
||
<p> | <p> | ||
<a name=sudo></a> | <a name=sudo></a> | ||
<li><font color=#009000><strong>039: SECURITY FIX: Feb 22, 2001</strong></font><br> | <li><font color=#009000><strong>039: SECURITY FIX: Feb 22, 2001</strong></font><br> | ||
There is a non-exploitable buffer overflow in | There is an exploitable heap corruption bug in | ||
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=sudo&sektion=8">sudo</a>. | |||
<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/039_sudo.patch">A | |||
source code patch exists which remedies the problem.</a><br> | |||
<p> | |||
<a name=named></a> | |||
<li><font color=#009000><strong>038: SECURITY FIX: Jan 29, 2001</strong></font><br> | |||
Merge <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=named&sektion=8">named</a> with ISC BIND 4.9.8-REL, which fixes some buffer vulnerabilities.<br> | |||
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/038_named.patch">A source code patch exists which remedies the problem.</a><br> | <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/038_named.patch">A source code patch exists which remedies the problem.</a><br> | ||
<p> | <p> | ||
<a name=ftpd></a> | <a name=ftpd></a> |