=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata31.html,v retrieving revision 1.11 retrieving revision 1.12 diff -u -r1.11 -r1.12 --- www/errata31.html 2003/02/23 17:21:50 1.11 +++ www/errata31.html 2003/02/23 20:21:41 1.12 @@ -57,7 +57,8 @@
  • 021: SECURITY FIX: February 23, 2003
    In ssl(8) an information leak can occur via timing by performing a MAC computation -even if incorrrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes in memory allocation routines. +even if incorrrect block cipher padding has been found, this is a +countermeasure. Also, check for negative sizes in memory allocation routines.
    A source code patch exists which fixes these two issues.

    @@ -69,7 +70,7 @@ user running cvs. This is only an issue when the cvs command is being run on a user's behalf as a different user. This means that, in most cases, the issue only exists for cvs configurations that use -the pserver client/server connection method. +the pserver client/server connection method.
    A source code patch exists which remedies the problem.

    @@ -303,7 +304,7 @@


    OpenBSD www@openbsd.org -
    $OpenBSD: errata31.html,v 1.11 2003/02/23 17:21:50 miod Exp $ +
    $OpenBSD: errata31.html,v 1.12 2003/02/23 20:21:41 brad Exp $