===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.316
retrieving revision 1.317
diff -u -r1.316 -r1.317
--- www/errata.html 2001/03/03 16:57:44 1.316
+++ www/errata.html 2001/03/18 18:18:46 1.317
@@ -45,6 +45,14 @@
All architectures
+
+- 024: SECURITY FIX: Mar 18, 2001
+The readline library shipped with OpenBSD allows history files creation with
+a permissive umask. This can lead to the leakage of sensitive information
+in applications that use passwords and the like during user interaction
+(one such application is mysql).
+A source code patch exists which remedies the problem.
+
- 023: SECURITY FIX: Mar 2, 2001
Insufficient checks in the IPSEC AH IPv4 option handling code can lead to a buffer overrun leading to a remote DoS. This option is not on by default.
@@ -349,7 +357,7 @@
www@openbsd.org
-
$OpenBSD: errata.html,v 1.316 2001/03/03 16:57:44 horacio Exp $
+
$OpenBSD: errata.html,v 1.317 2001/03/18 18:18:46 millert Exp $