===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata31.html,v
retrieving revision 1.10
retrieving revision 1.11
diff -u -r1.10 -r1.11
--- www/errata31.html 2003/01/21 03:47:10 1.10
+++ www/errata31.html 2003/02/23 17:21:50 1.11
@@ -53,6 +53,14 @@
All architectures
+
+- 021: SECURITY FIX: February 23, 2003
+In
+ssl(8) an information leak can occur via timing by performing a MAC computation
+even if incorrrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes in memory allocation routines.
+A
+source code patch exists which fixes these two issues.
+
- 020: SECURITY FIX: January 20, 2003
A double free in
@@ -295,7 +303,7 @@
www@openbsd.org
-
$OpenBSD: errata31.html,v 1.10 2003/01/21 03:47:10 millert Exp $
+
$OpenBSD: errata31.html,v 1.11 2003/02/23 17:21:50 miod Exp $