===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.561
retrieving revision 1.562
diff -u -r1.561 -r1.562
--- www/errata.html 2006/09/02 23:58:06 1.561
+++ www/errata.html 2006/09/08 20:35:11 1.562
@@ -75,6 +75,22 @@
+-
+010: SECURITY FIX: September 8, 2006 All architectures
+Two Denial of Service issues have been found with BIND.
+An attacker who can perform recursive lookups on a DNS server and is able
+to send a sufficiently large number of recursive queries, or is able to
+get the DNS server to return more than one SIG(covered) RRsets can stop
+the functionality of the DNS service.
+An attacker querying an authoritative DNS server serving a RFC 2535
+DNSSEC zone may be able to crash the DNS server.
+CVE-2006-4095
+CVE-2006-4096
+
+
+A source code patch exists which remedies this problem.
+
+
-
009: SECURITY FIX: September 2, 2006 All architectures
Due to the failure to correctly validate LCP configuration option lengths,
@@ -212,7 +228,7 @@
www@openbsd.org
-
$OpenBSD: errata.html,v 1.561 2006/09/02 23:58:06 brad Exp $
+
$OpenBSD: errata.html,v 1.562 2006/09/08 20:35:11 brad Exp $