version 1.3, 2004/03/30 06:36:36 |
version 1.4, 2004/05/05 07:35:16 |
|
|
<a name="all"></a> |
<a name="all"></a> |
<h3><font color="#e00000">All architectures</font></h3> |
<h3><font color="#e00000">All architectures</font></h3> |
<ul> |
<ul> |
|
<li><a name="cvs"></a> |
|
<font color="#009000"><strong>017: SECURITY FIX: May 5, |
|
2004</strong></font><br> |
|
Pathname validation problems have been found in |
|
<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=cvs&apropos=0&sektion=1&manpath=OpenBSD+Current&arch=i386&format=html">cvs(1)</a>, |
|
allowing malicious clients to create files outside the repository, allowing |
|
malicious servers to overwrite files outside the local CVS tree on |
|
the client and allowing clients to check out files outside the CVS |
|
repository. |
|
<br> |
|
<a href="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/017_cvs.patch"> |
|
A source code patch exists which remedies this problem</a>.<br> |
|
<p> |
<li><a name="openssl"></a> |
<li><a name="openssl"></a> |
<font color="#009000"><strong>016: RELIABILITY FIX: March 17, |
<font color="#009000"><strong>016: RELIABILITY FIX: March 17, |
2004</strong></font><br> |
2004</strong></font><br> |