===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata44.html,v
retrieving revision 1.7
retrieving revision 1.8
diff -c -r1.7 -r1.8
*** www/errata44.html 2008/11/19 11:19:06 1.7
--- www/errata44.html 2009/01/09 13:13:58 1.8
***************
*** 85,90 ****
--- 85,103 ----
+ -
+ 007: SECURITY FIX: January 9, 2009 All architectures
+ The OpenSSL libraries did not correctly check the return value from
+ certain verifiction functions, allowing validation to be bypassed and
+ permitting a remote attacker to conduct a "man in the middle attack"
+ against SSL/TLS connections if the server is configured with a DSA or ECDSA
+ certificate.
+ CVE-2008-5077.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
006: RELIABILITY FIX: November 19, 2008 All architectures
Due to changes in the options handling this caused problems with some
***************
*** 183,189 ****
www@openbsd.org
!
$OpenBSD: errata44.html,v 1.7 2008/11/19 11:19:06 brad Exp $