aboutsummaryrefslogtreecommitdiff
path: root/release
diff options
context:
space:
mode:
authorBruce A. Mah <bmah@FreeBSD.org>2002-05-29 18:27:14 +0000
committerBruce A. Mah <bmah@FreeBSD.org>2002-05-29 18:27:14 +0000
commit70f48510bb4ac8ada72096547d3311af474019a6 (patch)
treecd7c96bc10c77dd8462c001db2b762e40a53a9a6 /release
parente2f8ed516ab528d2a9eaa468a78db9e8f79697f6 (diff)
Notes
Diffstat (limited to 'release')
-rw-r--r--release/doc/en_US.ISO8859-1/relnotes/article.sgml13
-rw-r--r--release/doc/en_US.ISO8859-1/relnotes/common/new.sgml13
2 files changed, 24 insertions, 2 deletions
diff --git a/release/doc/en_US.ISO8859-1/relnotes/article.sgml b/release/doc/en_US.ISO8859-1/relnotes/article.sgml
index 103fe60d0bddf..bae992ccbfeb2 100644
--- a/release/doc/en_US.ISO8859-1/relnotes/article.sgml
+++ b/release/doc/en_US.ISO8859-1/relnotes/article.sgml
@@ -1788,7 +1788,18 @@ options HZ=1000 # not compulsory but strongly recommended</programlisting>
cache (<quote>syncache</quote>), which could allow a remote
attacker to deny access to a service when accept filters
(see &man.accept.filter.9;) were in use. This bug has been
- fixed. &merged;</para>
+ fixed; for more information, see security advisory <ulink
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:26.accept.asc">FreeBSD-SA-02:26</ulink>.
+ &merged;</para>
+
+ <para>Due to a bug in &man.rc.8;'s use of shell globbing, users
+ may be able to remove the contents of arbitrary files if
+ <filename>/tmp/.X11-unix</filename> does not exist and the
+ system can be made to reboot. This bug has been corrected (see
+ security advisory <ulink
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:27.rc.asc">FreeBSD-SA-02:27</ulink>).
+ &merged;</para>
+
</sect2>
<sect2 id="userland">
diff --git a/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml b/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml
index 103fe60d0bddf..bae992ccbfeb2 100644
--- a/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml
+++ b/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml
@@ -1788,7 +1788,18 @@ options HZ=1000 # not compulsory but strongly recommended</programlisting>
cache (<quote>syncache</quote>), which could allow a remote
attacker to deny access to a service when accept filters
(see &man.accept.filter.9;) were in use. This bug has been
- fixed. &merged;</para>
+ fixed; for more information, see security advisory <ulink
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:26.accept.asc">FreeBSD-SA-02:26</ulink>.
+ &merged;</para>
+
+ <para>Due to a bug in &man.rc.8;'s use of shell globbing, users
+ may be able to remove the contents of arbitrary files if
+ <filename>/tmp/.X11-unix</filename> does not exist and the
+ system can be made to reboot. This bug has been corrected (see
+ security advisory <ulink
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:27.rc.asc">FreeBSD-SA-02:27</ulink>).
+ &merged;</para>
+
</sect2>
<sect2 id="userland">