2002-Aug-02
Worked on binary updates.Reviewed a lot of OpenBSD and FreeBSD security advisories and compared with NetBSD code.
Send-pr: security/17818: insecure bzip2 on netbsd-1-5. It opened files insecurely, set modes late (race condition), and may use a symlink's permissions instead of the file it references. This code has been rewritten and new code is in newer netbsd-1-6. I assume since I filed it as "security" it wasn't archived and was not sent to the netbsd-bugs list.