===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata44.html,v
retrieving revision 1.2
retrieving revision 1.3
diff -c -r1.2 -r1.3
*** www/errata44.html 2008/08/24 19:10:08 1.2
--- www/errata44.html 2008/11/02 05:30:23 1.3
***************
*** 85,92 ****
--- 85,111 ----
! -
! 002: RELIABILITY FIX: November 2, 2008 All architectures
! Due to a bug in the vr(4) driver it is possible for a system using the vr(4)
! driver to panic under heavy load if the RX path runs out of mbufs.
!
!
! A source code patch exists which remedies this problem.
!
+
-
+ 001: SECURITY FIX: November 2, 2008 All architectures
+ The Neighbor Discovery Protocol (ndp) did not correctly verify neighbor
+ solicitation requests maybe allowing a nearby attacker to intercept traffic.
+ The attacker must have IPv6 connectivity to the same router as their target for
+ this vulnerability to be exploited.
+ CVE-2008-2476.
+
+
+ A source code patch exists which remedies this problem.
+
+
***************
*** 123,129 ****
www@openbsd.org
!
$OpenBSD: errata44.html,v 1.2 2008/08/24 19:10:08 deraadt Exp $