From e64d3eba2e084e8cfebf57b7653f5658120eb38c Mon Sep 17 00:00:00 2001 From: Frank Benkstein Date: Wed, 28 Nov 2007 14:16:56 +0100 Subject: [PATCH] ChangeLog: reword security description --- ChangeLog | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/ChangeLog b/ChangeLog index 5b201c4..a3f0271 100644 --- a/ChangeLog +++ b/ChangeLog @@ -2,12 +2,12 @@ XXXX-XX-XX Frank Benkstein vlock 2.2 rc3 - * A critical security problem was fixed: + * A critical security problem (local root exploit) was fixed: Previous versions of vlock (since 2.2 alpha1) contained a serious flaw - that allowed any user to execute arbitrary code as root (local root - exploit). This was possible because plugin names could contain "../" thus - escaping the pre-defined plugin directory. All users of vlock 2.2 - development versions are advised to update. + that allowed any user to execute arbitrary code as root . This was + possible because plugin names could contain "../" thus escaping the + pre-defined plugin directory. All users of vlock 2.2 development versions + are advised to update. 2007-11-26 Frank Benkstein -- 2.11.4.GIT