===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata46.html,v
retrieving revision 1.4
retrieving revision 1.5
diff -u -r1.4 -r1.5
--- www/errata46.html 2009/10/28 20:23:42 1.4
+++ www/errata46.html 2009/11/26 10:10:35 1.5
@@ -86,6 +86,17 @@
+-
+004: SECURITY FIX: November 26, 2009 All architectures
+The SSL/TLS protocol is subject to man-in-the-middle attacks related to
+renegotiation (see CVE-2009-3555, draft-ietf-tls-renegotiation-00).
+OpenSSL permitted this protocol feature by default and had no way to
+disable it.
+
+
+A source code patch exists which remedies this problem.
+
+
-
003: RELIABILITY FIX: October 28, 2009 All architectures
getsockopt(2) with any of IP_AUTH_LEVEL, IP_ESP_TRANS_LEVEL, IP_ESP_NETWORK_LEVEL,
@@ -151,7 +162,7 @@
www@openbsd.org
-
$OpenBSD: errata46.html,v 1.4 2009/10/28 20:23:42 deraadt Exp $
+
$OpenBSD: errata46.html,v 1.5 2009/11/26 10:10:35 sthen Exp $