===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata43.html,v
retrieving revision 1.12
retrieving revision 1.13
diff -u -r1.12 -r1.13
--- www/errata43.html 2008/10/02 18:44:06 1.12
+++ www/errata43.html 2009/01/09 13:13:58 1.13
@@ -85,6 +85,19 @@
+-
+007: SECURITY FIX: January 9, 2009 All architectures
+The OpenSSL libraries did not correctly check the return value from
+certain verifiction functions, allowing validation to be bypassed and
+permitting a remote attacker to conduct a "man in the middle attack"
+against SSL/TLS connections if the server is configured with a DSA or ECDSA
+certificate.
+CVE-2008-5077.
+
+
+A source code patch exists which remedies this problem.
+
+
-
006: SECURITY FIX: October 2, 2008 All architectures
The Neighbor Discovery Protocol (ndp) did not correctly verify neighbor
@@ -191,7 +204,7 @@
www@openbsd.org
-
$OpenBSD: errata43.html,v 1.12 2008/10/02 18:44:06 brad Exp $
+
$OpenBSD: errata43.html,v 1.13 2009/01/09 13:13:58 djm Exp $