Subject: Re: [venglin@freebsd.lublin.pl: local root compromise in openbsd 3.0 and below]
To: Steven M. Bellovin <smb@research.att.com>
From: Herb Peyerl <hpeyerl@beer.org>
List: tech-security
Date: 04/13/2002 07:34:55
"Steven M. Bellovin" <smb@research.att.com>  wrote:
 > In message <Pine.LNX.4.43.0204130431040.14412-100000@pilchuck.reedmedia.net>, "
 > Jeremy C. Reed" writes:
 > 
 > >
 > >I am curious why Steven and Todd said this is an "old" bug.
 > >
 > >Looking at OpenBSD back to beginning I don't see it. And looking at
 > >src/usr.bin/mail/collect.c dated Apr. 18, 1991 from 386bsd-0.0, I don't
 > >see the bug.
 > >
 > >When was it originally fixed? (In the 80's?)
 > 
 > That sounds about right...


There's pretty much no excuse for that.  I wonder how many other ancient
bugs OpenBSD has put back in the OS?