A relatively obscure one-byte buffer overflow bug present in ftpd(8) turnsout to be a serious problem, yielding remote users root access undercertain conditions.
Systems running with procfs enabled and mounted are vulnerable to having the stderr output of setuid processes directed onto a pre-seeked descriptor onto the stack in their own procfs memory.Note that procfs is not mounted by default in OpenBSD.