version 1.14, 2002/03/15 16:55:06 |
version 1.15, 2002/04/11 18:39:22 |
|
|
<a name=all></a> |
<a name=all></a> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<li><h3><font color=#e00000>All architectures</font></h3> |
<ul> |
<ul> |
|
<a name=mail></a> |
|
<li><font color=#009000><strong>023: SECURITY FIX: April 11, 2002</strong></font><br> |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=mail&sektion=1">mail(1)</a> |
|
will process tilde escapes even in non-interactive mode. |
|
This can lead to a local root compromise. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/023_mail.patch">A source code patch exists which remedies the problem</a>. |
|
<p> |
<a name=zlib></a> |
<a name=zlib></a> |
<li><font color=#009000><strong>022: RELIABILITY FIX: March 13, 2002</strong></font><br> |
<li><font color=#009000><strong>022: RELIABILITY FIX: March 13, 2002</strong></font><br> |
Under some circumstances the zlib compression library can free dynamically |
Under some circumstances the zlib compression library can free dynamically |