[BACK]Return to security.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/security.html between version 1.236 and 1.237

version 1.236, 2003/02/25 01:40:44 version 1.237, 2003/03/03 17:29:34
Line 196 
Line 196 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href=errata.html#sendmail>March 3, 2003:
           A buffer overflow in the envelope comments processing in
           sendmail(8) may allow an attacker to gain root privileges.</a>
 <li><a href=errata.html#httpd>February 25, 2003:  <li><a href=errata.html#httpd>February 25, 2003:
         httpd(8) leaks file inode numbers via ETag header as well as          httpd(8) leaks file inode numbers via ETag header as well as
         child PIDs in multipart MIME boundary generation. This could          child PIDs in multipart MIME boundary generation. This could
Line 239 
Line 242 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href=errata31.html#sendmail>March 3, 2003:
           A buffer overflow in the envelope comments processing in
           sendmail(8) may allow an attacker to gain root privileges.</a>
 <li><a href=errata31.html#ssl2>February 23, 2003:  <li><a href=errata31.html#ssl2>February 23, 2003:
         In ssl(8) an information leak can occur via timing by performing          In ssl(8) an information leak can occur via timing by performing
         a MAC computation even if incorrect block cipher padding has          a MAC computation even if incorrect block cipher padding has

Legend:
Removed from v.1.236  
changed lines
  Added in v.1.237