===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata46.html,v
retrieving revision 1.4
retrieving revision 1.5
diff -c -r1.4 -r1.5
*** www/errata46.html 2009/10/28 20:23:42 1.4
--- www/errata46.html 2009/11/26 10:10:35 1.5
***************
*** 86,91 ****
--- 86,102 ----
+ -
+ 004: SECURITY FIX: November 26, 2009 All architectures
+ The SSL/TLS protocol is subject to man-in-the-middle attacks related to
+ renegotiation (see CVE-2009-3555, draft-ietf-tls-renegotiation-00).
+ OpenSSL permitted this protocol feature by default and had no way to
+ disable it.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
003: RELIABILITY FIX: October 28, 2009 All architectures
getsockopt(2) with any of IP_AUTH_LEVEL, IP_ESP_TRANS_LEVEL, IP_ESP_NETWORK_LEVEL,
***************
*** 151,157 ****
www@openbsd.org
!
$OpenBSD: errata46.html,v 1.4 2009/10/28 20:23:42 deraadt Exp $