=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/errata55.html,v retrieving revision 1.25 retrieving revision 1.26 diff -u -r1.25 -r1.26 --- www/errata55.html 2014/10/19 21:08:19 1.25 +++ www/errata55.html 2014/11/17 19:55:00 1.26 @@ -220,6 +220,18 @@ A source code patch exists which remedies this problem.

+

  • +013: SECURITY FIX: November 17, 2014All architectures
    +PF rules of the form "pass from {192.0.2.1 2001:db8::1} to (pppoe0)" will +apply an incorrect /32 mask to the dynamic IPv6 address, allowing access to +a wide address range rather than the intended single host. +As a workaround, list the IPv4 address last, i.e. "{2001:db8::1 192.0.2.1}". +
    + +A source code patch exists which remedies this problem. +

    +