===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.562
retrieving revision 1.563
diff -c -r1.562 -r1.563
*** www/errata.html 2006/09/08 20:35:11 1.562
--- www/errata.html 2006/09/09 03:04:22 1.563
***************
*** 75,80 ****
--- 75,91 ----
+ -
+ 011: SECURITY FIX: September 8, 2006 All architectures
+ Due to incorrect PKCS#1 v1.5 padding validation in OpenSSL, it is possible for
+ an attacker to construct an invalid signature which OpenSSL would accept as a
+ valid PKCS#1 v1.5 signature.
+ CVE-2006-4339
+
+
+ A source code patch exists which remedies this problem.
+
+
-
010: SECURITY FIX: September 8, 2006 All architectures
Two Denial of Service issues have been found with BIND.
***************
*** 228,234 ****
www@openbsd.org
!
$OpenBSD: errata.html,v 1.562 2006/09/08 20:35:11 brad Exp $