===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata43.html,v
retrieving revision 1.18
retrieving revision 1.19
diff -c -r1.18 -r1.19
*** www/errata43.html 2009/02/18 22:09:47 1.18
--- www/errata43.html 2009/02/22 22:09:38 1.19
***************
*** 85,90 ****
--- 85,102 ----
+ -
+ 011: SECURITY FIX: February 22, 2009 All architectures
+ sudo(8) may allow a user listed in the sudoers file to run a command
+ as a different user than their access rule specifies when a Unix
+ group is used in the RunAs portion of the rule. The bug only manifests
+ when the user being granted privileges is also a member of the group
+ in the RunAs portion of the rule.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
010: RELIABILITY FIX: February 18, 2009 All architectures
bgpd(8) did not correctly prepend its own AS to very long AS paths, causing
***************
*** 236,242 ****
www@openbsd.org
!
$OpenBSD: errata43.html,v 1.18 2009/02/18 22:09:47 claudio Exp $