=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v retrieving revision 1.427 retrieving revision 1.428 diff -c -r1.427 -r1.428 *** www/errata.html 2003/02/22 23:16:53 1.427 --- www/errata.html 2003/02/23 00:14:38 1.428 *************** *** 57,66 ****
  • 007: SECURITY FIX: February 22, 2003
    In ssl(8) an information leak can occur via timing by performing a MAC computation ! even if incorrrect block cipher padding has been found. This fix is a ! countermeasure against active attacks where the attacker has to distinguish ! between bad padding and a MAC verification error. (CAN-2003-0078). ! Also, check for negative sizes in memory allocation routines. A source code patch exists which fixes these two issues.

    --- 57,63 ----

  • 007: SECURITY FIX: February 22, 2003
    In ssl(8) an information leak can occur via timing by performing a MAC computation ! even if incorrrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes in memory allocation routines. A source code patch exists which fixes these two issues.

    *************** *** 207,213 ****


    OpenBSD www@openbsd.org !
    $OpenBSD: errata.html,v 1.427 2003/02/22 23:16:53 margarida Exp $ --- 204,210 ----
    OpenBSD www@openbsd.org !
    $OpenBSD: errata.html,v 1.428 2003/02/23 00:14:38 margarida Exp $