summaryrefslogtreecommitdiffstats
path: root/release/doc
diff options
context:
space:
mode:
authorbmah <bmah@FreeBSD.org>2003-03-03 18:20:00 +0000
committerbmah <bmah@FreeBSD.org>2003-03-03 18:20:00 +0000
commite1ea0f1223f8b01f14f703a0d4364020a3d28ff2 (patch)
treee2c1707cc9970485a5c0ca2b67bb9c6c530b33aa /release/doc
parentace1448c0d6531fe14161f95ed67d8c340c0b977 (diff)
downloadFreeBSD-src-e1ea0f1223f8b01f14f703a0d4364020a3d28ff2.zip
FreeBSD-src-e1ea0f1223f8b01f14f703a0d4364020a3d28ff2.tar.gz
New errata item: SA-03:04.
Diffstat (limited to 'release/doc')
-rw-r--r--release/doc/en_US.ISO8859-1/errata/article.sgml8
1 files changed, 8 insertions, 0 deletions
diff --git a/release/doc/en_US.ISO8859-1/errata/article.sgml b/release/doc/en_US.ISO8859-1/errata/article.sgml
index 64b9d47..964722f 100644
--- a/release/doc/en_US.ISO8859-1/errata/article.sgml
+++ b/release/doc/en_US.ISO8859-1/errata/article.sgml
@@ -133,6 +133,14 @@
given in security advisory <ulink
url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:03.syncookies.asc">FreeBSD-SA-03:03</ulink>.</para>
+ <para>Due to a buffer overflow in header parsing, a remote
+ attacker could create a specially crafted message that may cause
+ <application>sendmail</application> to execute arbitrary code
+ with the privileges of the user running sendmail, typically
+ <username>root</username>. More information, including pointers
+ to patches, can be found in security advisory <ulink
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:04.sendmail.asc">FreeBSD-SA-03:04</ulink>.</para>
+
</sect1>
<sect1 id="late-news">
OpenPOWER on IntegriCloud