FreeBSD rc Arbitrary Directory Deletion Vulnerability Solution:
FreeBSD has corrected this vulnerability in their current FreeBSD 4.5-RELEASE tree.
A patch is also available:
FreeBSD FreeBSD 4.5 -RELEASE
-
FreeBSD rc.patch
From FreeBSD-SA-02:27.rc:2) To patch your present system:a) Download the relevant patch from the location below, and verify thedetached PGP signature using your PGP utility.# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:27/rc.patch# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:27/rc.patch
FreeBSD FreeBSD 4.5 -STABLE
-
FreeBSD rc.patch
From FreeBSD-SA-02:27.rc:2) To patch your present system:a) Download the relevant patch from the location below, and verify thedetached PGP signature using your PGP utility.# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:27/rc.patch# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-02:27/rc.patch