Subject: Re: [venglin@freebsd.lublin.pl: local root compromise in openbsd 3.0 and below]
To: Steven M. Bellovin <smb@research.att.com>
From: Herb Peyerl <hpeyerl@beer.org>
List: tech-security
Date: 04/13/2002 07:34:55
"Steven M. Bellovin" <smb@research.att.com> wrote:
> In message <Pine.LNX.4.43.0204130431040.14412-100000@pilchuck.reedmedia.net>, "
> Jeremy C. Reed" writes:
>
> >
> >I am curious why Steven and Todd said this is an "old" bug.
> >
> >Looking at OpenBSD back to beginning I don't see it. And looking at
> >src/usr.bin/mail/collect.c dated Apr. 18, 1991 from 386bsd-0.0, I don't
> >see the bug.
> >
> >When was it originally fixed? (In the 80's?)
>
> That sounds about right...
There's pretty much no excuse for that. I wonder how many other ancient
bugs OpenBSD has put back in the OS?