version 1.21, 2001/06/07 06:19:49 |
version 1.22, 2001/06/09 16:39:03 |
|
|
<a name=httpd></a> |
<a name=httpd></a> |
<li><font color=#009000><strong>031: SECURITY FIX: Oct 18, 2000</strong></font><br> |
<li><font color=#009000><strong>031: SECURITY FIX: Oct 18, 2000</strong></font><br> |
Apache has several bugs in <tt>mod_rewrite</tt> and <tt>mod_vhost_alias</tt> |
Apache has several bugs in <tt>mod_rewrite</tt> and <tt>mod_vhost_alias</tt> |
that could cause arbirtary files accessible to the www user on the server |
that could cause arbitrary files accessible to the www user on the server |
to be exposed under certain configurations when these modules are used. |
to be exposed under certain configurations when these modules are used. |
(These modules are not active by default). |
(These modules are not active by default). |
<br> |
<br> |
|
|
<li><font color=#009000><strong>020: KERNEL BUG: July 10, 2000</strong></font><br> |
<li><font color=#009000><strong>020: KERNEL BUG: July 10, 2000</strong></font><br> |
As originally shipped, the pmax port would fail to install due to |
As originally shipped, the pmax port would fail to install due to |
<b>/kern/msgbuf</b> bugs.<br> |
<b>/kern/msgbuf</b> bugs.<br> |
The neccessary fixes have been merged, |
The necessary fixes have been merged, |
and the binaries needed re-released on the FTP site.<br> |
and the binaries needed re-released on the FTP site.<br> |
However, the 2.7 <b>srcsys.tar.gz</b> file has not been updated.<br> |
However, the 2.7 <b>srcsys.tar.gz</b> file has not been updated.<br> |
If you recompile a kernel, you should use either the |
If you recompile a kernel, you should use either the |