version 1.12, 2001/02/22 14:45:12 |
version 1.13, 2001/03/18 18:18:46 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=readline></a> |
|
<li><font color=#009000><strong>040: SECURITY FIX: Mar 18, 2001</strong></font>< |
|
br> |
|
The readline library shipped with OpenBSD allows history files creation with |
|
a permissive umask. This can lead to the leakage of sensitive information |
|
in applications that use passwords and the like during user interaction |
|
(one such application is mysql). Additionally, if the HOME environment |
|
variable is not set, the current working directory is used; this patch |
|
disables the history file if HOME is not set. |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/040_readline.patch |
|
">A source code patch exists which remedies the problem.</a><br> |
|
<p> |
<a name=sudo></a> |
<a name=sudo></a> |
<li><font color=#009000><strong>039: SECURITY FIX: Feb 22, 2001</strong></font><br> |
<li><font color=#009000><strong>039: SECURITY FIX: Feb 22, 2001</strong></font><br> |
There is a buffer overflow in |
There is a buffer overflow in |