===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.567
retrieving revision 1.568
diff -c -r1.567 -r1.568
*** www/errata.html 2006/10/07 18:32:35 1.567
--- www/errata.html 2006/10/12 07:05:21 1.568
***************
*** 74,79 ****
--- 74,92 ----
+ -
+ 015: SECURITY FIX: October 12, 2006 All architectures
+ Fix 2 security bugs found in OpenSSH. A pre-authenication denial of service (found
+ by Tavis Ormandy) that would cause
+ sshd(8)
+ to spin until the login grace time expired.
+ An unsafe signal handler (found by Mark Dowd) that is vulnerable to a race condition
+ that could be exploited to perform a pre-authentication denial of service.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
014: SECURITY FIX: October 7, 2006 All architectures
Fix for an integer overflow in
***************
*** 279,285 ****
www@openbsd.org
!
$OpenBSD: errata.html,v 1.567 2006/10/07 18:32:35 brad Exp $