=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata31.html,v retrieving revision 1.14 retrieving revision 1.15 diff -c -r1.14 -r1.15 *** www/errata31.html 2003/03/03 18:16:13 1.14 --- www/errata31.html 2003/03/04 13:03:43 1.15 *************** *** 65,71 ****
  • 021: SECURITY FIX: February 23, 2003
    In ssl(8) an information leak can occur via timing by performing a MAC computation ! even if incorrrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes in memory allocation routines.
    A source code patch exists which fixes these two issues. --- 65,71 ----
  • 021: SECURITY FIX: February 23, 2003
    In ssl(8) an information leak can occur via timing by performing a MAC computation ! even if incorrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes in memory allocation routines.
    A source code patch exists which fixes these two issues. *************** *** 312,318 ****
    OpenBSD www@openbsd.org !
    $OpenBSD: errata31.html,v 1.14 2003/03/03 18:16:13 jufi Exp $ --- 312,318 ----
    OpenBSD www@openbsd.org !
    $OpenBSD: errata31.html,v 1.15 2003/03/04 13:03:43 nick Exp $