===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.425
retrieving revision 1.426
diff -u -r1.425 -r1.426
--- www/errata.html 2003/01/21 03:47:10 1.425
+++ www/errata.html 2003/02/22 22:50:04 1.426
@@ -53,6 +53,16 @@
All architectures
+
+- 007: SECURITY FIX: February 22, 2003
+An information leak can occur via timing by performing a MAC computation
+even if incorrrect block cipher padding has been found. This fix is a
+countermeasure against active attacks where the attacker has to distinguish
+between bad padding and a MAC verification error. (CAN-2003-0078).
+Also, check for negative sizes in memory allocation routines.
+A
+source code patch exists which fixes these two issues.
+
- 006: SECURITY FIX: January 20, 2003
A double free in
@@ -196,7 +206,7 @@
www@openbsd.org
-
$OpenBSD: errata.html,v 1.425 2003/01/21 03:47:10 millert Exp $
+
$OpenBSD: errata.html,v 1.426 2003/02/22 22:50:04 margarida Exp $