===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.561
retrieving revision 1.562
diff -c -r1.561 -r1.562
*** www/errata.html 2006/09/02 23:58:06 1.561
--- www/errata.html 2006/09/08 20:35:11 1.562
***************
*** 75,80 ****
--- 75,96 ----
+ -
+ 010: SECURITY FIX: September 8, 2006 All architectures
+ Two Denial of Service issues have been found with BIND.
+ An attacker who can perform recursive lookups on a DNS server and is able
+ to send a sufficiently large number of recursive queries, or is able to
+ get the DNS server to return more than one SIG(covered) RRsets can stop
+ the functionality of the DNS service.
+ An attacker querying an authoritative DNS server serving a RFC 2535
+ DNSSEC zone may be able to crash the DNS server.
+ CVE-2006-4095
+ CVE-2006-4096
+
+
+ A source code patch exists which remedies this problem.
+
+
-
009: SECURITY FIX: September 2, 2006 All architectures
Due to the failure to correctly validate LCP configuration option lengths,
***************
*** 212,218 ****
www@openbsd.org
!
$OpenBSD: errata.html,v 1.561 2006/09/02 23:58:06 brad Exp $