===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.316
retrieving revision 1.317
diff -c -r1.316 -r1.317
*** www/errata.html 2001/03/03 16:57:44 1.316
--- www/errata.html 2001/03/18 18:18:46 1.317
***************
*** 45,50 ****
--- 45,58 ----
All architectures
+
+ - 024: SECURITY FIX: Mar 18, 2001
+ The readline library shipped with OpenBSD allows history files creation with
+ a permissive umask. This can lead to the leakage of sensitive information
+ in applications that use passwords and the like during user interaction
+ (one such application is mysql).
+ A source code patch exists which remedies the problem.
+
- 023: SECURITY FIX: Mar 2, 2001
Insufficient checks in the IPSEC AH IPv4 option handling code can lead to a buffer overrun leading to a remote DoS. This option is not on by default.
***************
*** 349,355 ****
www@openbsd.org
!
$OpenBSD: errata.html,v 1.316 2001/03/03 16:57:44 horacio Exp $