=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata44.html,v retrieving revision 1.18 retrieving revision 1.19 diff -c -r1.18 -r1.19 *** www/errata44.html 2009/04/11 23:46:45 1.18 --- www/errata44.html 2009/04/13 08:45:40 1.19 *************** *** 91,97 **** When pf attempts to perform translation on a specially crafted IP datagram, a null pointer dereference will occur, resulting in a kernel panic. In certain configurations this may be triggered by a remote attacker. !

Restricting translation rules to protocols that are specific to the IP version in use, is an effective workaround until the patch can be installed. As an example, for IPv4 nat/binat/rdr rules you can use: --- 91,97 ---- When pf attempts to perform translation on a specially crafted IP datagram, a null pointer dereference will occur, resulting in a kernel panic. In certain configurations this may be triggered by a remote attacker. !
Restricting translation rules to protocols that are specific to the IP version in use, is an effective workaround until the patch can be installed. As an example, for IPv4 nat/binat/rdr rules you can use: *************** *** 279,285 ****


OpenBSD www@openbsd.org !
$OpenBSD: errata44.html,v 1.18 2009/04/11 23:46:45 sthen Exp $ --- 279,285 ----
OpenBSD www@openbsd.org !
$OpenBSD: errata44.html,v 1.19 2009/04/13 08:45:40 sthen Exp $