===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata36.html,v
retrieving revision 1.3
retrieving revision 1.4
diff -u -r1.3 -r1.4
--- www/errata36.html 2005/06/16 02:42:45 1.3
+++ www/errata36.html 2005/06/21 04:04:28 1.4
@@ -73,6 +73,18 @@
+-
+018: SECURITY FIX: June 20, 2005 All architectures
+Due to a race condition in its command pathname handling, a user with
+sudo(8)
+privileges may be able to run arbitrary commands if the user's entry
+is followed by an entry that grants sudo ALL privileges to
+another user.
+
+
+A source code patch exists which remedies this problem.
+
+
-
017: RELIABILITY FIX: June 15, 2005 All architectures
As discovered by Stefan Miltchev calling
@@ -293,7 +305,7 @@
www@openbsd.org
-
$OpenBSD: errata36.html,v 1.3 2005/06/16 02:42:45 brad Exp $
+
$OpenBSD: errata36.html,v 1.4 2005/06/21 04:04:28 millert Exp $