diff options
author | fn <fn@cvs.openbsd.org> | 1996-09-19 06:45:09 +0000 |
---|---|---|
committer | fn <fn@cvs.openbsd.org> | 1996-09-19 06:45:09 +0000 |
commit | 836acd6372e410c23f3ed28a59ed17cfa6ed382c (patch) | |
tree | 7e94011b0a18d4a2efbc1a475f03256a80ad0ee6 /usr.sbin/sendmail/RELEASE_NOTES | |
parent | 9a6d574f58db401cf9c5101d10c5ca03d30fc5bf (diff) |
bring up to 8.7.6
Diffstat (limited to 'usr.sbin/sendmail/RELEASE_NOTES')
-rw-r--r-- | usr.sbin/sendmail/RELEASE_NOTES | 12 |
1 files changed, 11 insertions, 1 deletions
diff --git a/usr.sbin/sendmail/RELEASE_NOTES b/usr.sbin/sendmail/RELEASE_NOTES index 7f212ec3e48..a4daceaf313 100644 --- a/usr.sbin/sendmail/RELEASE_NOTES +++ b/usr.sbin/sendmail/RELEASE_NOTES @@ -1,11 +1,21 @@ SENDMAIL RELEASE NOTES - @(#)RELEASE_NOTES 8.7.5.1 (Berkeley) 3/4/96 + @(#)RELEASE_NOTES 8.7.6.4 (Berkeley) 9/16/96 This listing shows the version of the sendmail binary, the version of the sendmail configuration files, the date of release, and a summary of the changes in that release. +8.7.6/8.7.3 96/09/17 + SECURITY: It is possible to force getpwuid to fail when writing the + queue file, causing sendmail to fall back to running programs + as the default user. This is not exploitable from off-site. + Workarounds include using a unique user for the DefaultUser + (old u & g options) and using smrsh as the local shell. + SECURITY: fix some buffer overruns; in at least one case this allows + a local user to get root. This is not known to be exploitable + from off-site. The workaround is to disable chfn(1) commands. + 8.7.5/8.7.3 96/03/04 Fix glitch in 8.7.4 when putting certain internal lines; this can in some case cause connections to hang. Patch from Eric |