OpenBSD Journal

a rexecd|rshd patch available for 3.0

Contributed by Dengue on from the errata dept.

Patch 016 is now available for OpenBSD 3.0. To quote errata.html :
"Under certain conditions, on systems using YP with netgroups in the password database, it is possible for the rexecd(8) and rshd(8) for the rexecd and rshd daemons to execute the shell from a different user's password entry. Due to a similar problem, atrun(8) may change to the wrong home directory when running at(1) jobs."

(Comments are closed)


Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]