[BACK]Return to errata28.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata28.html between version 1.17 and 1.18

version 1.17, 2001/08/29 22:25:27 version 1.18, 2001/09/12 13:52:39
Line 46 
Line 46 
 <a name=all></a>  <a name=all></a>
 <li><h3><font color=#e00000>All architectures</font></h3>  <li><h3><font color=#e00000>All architectures</font></h3>
 <ul>  <ul>
   <a name=uucp>
   <li><font color=#009000><strong>033: SECURITY FIX: September 11, 2001</strong></font><br>
   A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=uuxqt&sektion=8">uuxqt(8)</a>
   that may allow an attacker to run arbitrary commands as user uucp and
   use this to gain root access.
   The UUCP execution daemon, uuxqt(8), has a bug in its command line
   parsing routine may allow arbitrary commands to be run.  Because
   some UUCP commands are run as root (and daemon) from cron it is possible
   to leverage compromise of the UUCP user to gain root.
   <br>
   <a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/033_uucp.patch">A source code patch exists which remedies the problem</a>
   <p>
 <a name=lpd>  <a name=lpd>
 <li><font color=#009000><strong>032: SECURITY FIX: August 29, 2001</strong></font><br>  <li><font color=#009000><strong>032: SECURITY FIX: August 29, 2001</strong></font><br>
 A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lpd&sektion=8">lpd(8)</a>  A security hole exists in <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=lpd&sektion=8">lpd(8)</a>

Legend:
Removed from v.1.17  
changed lines
  Added in v.1.18