===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata48.html,v
retrieving revision 1.4
retrieving revision 1.5
diff -c -r1.4 -r1.5
*** www/errata48.html 2010/11/18 08:34:45 1.4
--- www/errata48.html 2010/12/17 16:36:18 1.5
***************
*** 87,92 ****
--- 87,116 ----
+ -
+ 006: RELIABILITY FIX: December 17, 2010 All architectures
+ Bring CBC oracle attack countermeasures to hardware crypto accelerator land.
+ This fixes aes-ni, via xcrypt and various drivers
+ (glxsb(4),
+ hifn(4),
+ safe(4)
+ and
+ ubsec(4)).
+
+
+ A source code patch exists which remedies this problem.
+
+
+
-
+ 005: SECURITY FIX: December 17, 2010 All architectures
+ Insufficent initialization of the pf rule structure in the ioctl
+ handler may allow userland to modify kernel memory. By default root
+ privileges are needed to add or modify pf rules.
+
+
+ A source code patch exists which remedies this problem.
+
+
-
004: RELIABILITY FIX: November 17, 2010 All architectures
Fix a flaw in the OpenSSL TLS server extension code parsing which could lead to
***************
*** 166,172 ****
www@openbsd.org
!
$OpenBSD: errata48.html,v 1.4 2010/11/18 08:34:45 jasper Exp $