=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/security.html,v retrieving revision 1.120 retrieving revision 1.121 diff -c -r1.120 -r1.121 *** www/security.html 1999/12/03 00:34:26 1.120 --- www/security.html 1999/12/04 19:59:19 1.121 *************** *** 197,202 **** --- 197,207 ---- USA version of libssl, is possibly exploitable in httpd, ssh, or isakmpd, if SSL/RSA features are enabled. (patch included). +
  • Dec 4, 1999: + Sendmail permitted any user to cause a aliases file wrap, + thus exposing the system to a race where the aliases file + did not exist. + (patch included).

    *************** *** 485,491 **** OpenBSD www@openbsd.org
    ! $OpenBSD: security.html,v 1.120 1999/12/03 00:34:26 deraadt Exp $ --- 490,496 ---- OpenBSD www@openbsd.org
    ! $OpenBSD: security.html,v 1.121 1999/12/04 19:59:19 deraadt Exp $