===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata45.html,v
retrieving revision 1.7
retrieving revision 1.8
diff -c -r1.7 -r1.8
*** www/errata45.html 2009/04/27 21:07:46 1.7
--- www/errata45.html 2009/07/02 21:55:17 1.8
***************
*** 85,91 ****
--- 85,104 ----
+ -
+ 006: RELIABILITY FIX: June 24, 2009 All architectures
+ An off-by-one error in the inflate function in Zlib.xs in the
+ Compress::Raw::Zlib perl module before 2.017 (CVE-2009-1391),
+ as used in AMaViS, SpamAssassin, and possibly other products,
+ allows context-dependent attackers to cause a denial of service
+ (hang or crash) via a crafted zlib compressed stream that
+ triggers a heap-based buffer overflow.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
005: RELIABILITY FIX: April 24, 2009 All architectures
On very high system load, an audio interrupt may occur while the
***************
*** 198,204 ****
www@openbsd.org
!
$OpenBSD: errata45.html,v 1.7 2009/04/27 21:07:46 ratchov Exp $