The ELF ld.so(1) fails to properly sanitize the environment.
There is a potential localhost security problem in cases we
have not found yet. This patch applies to all ELF-based systems
(m68k, m88k, and vax are a.out-based systems).
Patches for the respective releases:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.0/common/005_ldso.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/016_ldso.patch