• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

OpenBSD patches -including local root hole

n0cmonkey

Elite Member
comments on deadly.org



<< "The mail(1) program can be made to execute arbitrary code in non interactive mode. this can be exploited using cron and the system startup scripts (by any local user with no privs) a patch is and advisory is available on the advisory page.
the 2.9 patch is at ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/023_mail.patch the 3.0 patch is at ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.0/common/018_mail.patch

the fix has also been applied to the stable branches."
>>



There is an exploit in the wild for this one too, so if you have multiple users and you cant absolutely trust them all, fix this immediately (like 2 days ago).


OpenBSD errata page.
OpenBSD anoncvs page.

BUMPS and comments appreciated.
 
n0c, OT, but:

What is your gripe with FreeBSD (the link in your sig.)? There is usually some truthful intent even if it is a "joke" for you to have that link.

 


<< n0c, OT, but:

What is your gripe with FreeBSD (the link in your sig.)? There is usually some truthful intent even if it is a "joke" for you to have that link.
>>



Nothing major. I use FreeBSD on occassion. I like FreeBSD. If there was an OpenBSD spoof page like that Id throw that in there. If you cant laugh at yourself, who can you laugh at?
 


<< At FreeBSD, 28901219283 developers working on security patches for the next millenium on every single one of our 2 architectures to ensure maximum capabilities on patch adds and revisions. >>


for some reason that really cracks me up 😛
 


<<

<< At FreeBSD, 28901219283 developers working on security patches for the next millenium on every single one of our 2 architectures to ensure maximum capabilities on patch adds and revisions. >>


for some reason that really cracks me up 😛
>>



😉

They also have a linux.com one thats pretty funny.
 
Back
Top