===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata38.html,v
retrieving revision 1.18
retrieving revision 1.19
diff -u -r1.18 -r1.19
--- www/errata38.html 2006/10/07 18:32:35 1.18
+++ www/errata38.html 2006/10/12 07:05:21 1.19
@@ -74,6 +74,19 @@
+-
+020: SECURITY FIX: October 12, 2006 All architectures
+Fix 2 security bugs found in OpenSSH. A pre-authenication denial of service (found
+by Tavis Ormandy) that would cause
+sshd(8)
+to spin until the login grace time expired.
+An unsafe signal handler (found by Mark Dowd) that is vulnerable to a race condition
+that could be exploited to perform a pre-authentication denial of service.
+
+
+A source code patch exists which remedies this problem.
+
+
-
019: SECURITY FIX: October 7, 2006 All architectures
Fix for an integer overflow in
@@ -335,7 +348,7 @@
www@openbsd.org
-
$OpenBSD: errata38.html,v 1.18 2006/10/07 18:32:35 brad Exp $
+
$OpenBSD: errata38.html,v 1.19 2006/10/12 07:05:21 brad Exp $