===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata43.html,v
retrieving revision 1.12
retrieving revision 1.13
diff -c -r1.12 -r1.13
*** www/errata43.html 2008/10/02 18:44:06 1.12
--- www/errata43.html 2009/01/09 13:13:58 1.13
***************
*** 85,90 ****
--- 85,103 ----
+ -
+ 007: SECURITY FIX: January 9, 2009 All architectures
+ The OpenSSL libraries did not correctly check the return value from
+ certain verifiction functions, allowing validation to be bypassed and
+ permitting a remote attacker to conduct a "man in the middle attack"
+ against SSL/TLS connections if the server is configured with a DSA or ECDSA
+ certificate.
+ CVE-2008-5077.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
006: SECURITY FIX: October 2, 2008 All architectures
The Neighbor Discovery Protocol (ndp) did not correctly verify neighbor
***************
*** 191,197 ****
www@openbsd.org
!
$OpenBSD: errata43.html,v 1.12 2008/10/02 18:44:06 brad Exp $