===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.375
retrieving revision 1.376
diff -u -r1.375 -r1.376
--- www/errata.html 2002/03/08 19:50:52 1.375
+++ www/errata.html 2002/03/14 05:38:54 1.376
@@ -47,6 +47,16 @@
All architectures
+
+- 015: RELIABILITY FIX: March 13, 2002
+Under some circumstances the zlib compression library can free dynamically
+allocated memory twice. This is not a security issue on OpenBSD since the BSD
+free(3)
+function detects this.
+There is also a kernel zlib component that may be used by pppd and IPSec.
+The feasibility of attacking the kernel this way is currently unknown.
+A source code patch exists which remedies the problem.
+
- 014: SECURITY FIX: March 8, 2002
A local user can gain super-user privileges due to an off-by-one check
@@ -261,7 +271,7 @@
www@openbsd.org
-
$OpenBSD: errata.html,v 1.375 2002/03/08 19:50:52 provos Exp $
+
$OpenBSD: errata.html,v 1.376 2002/03/14 05:38:54 millert Exp $