[BACK]Return to security.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/security.html between version 1.334 and 1.335

version 1.334, 2006/11/04 03:02:28 version 1.335, 2006/11/04 21:28:18
Line 233 
Line 233 
   
 <p>  <p>
 <ul>  <ul>
 <li><a href="errata.html#systrace">Oct 7, 2006:  <li><a href="errata.html#systrace">Nov 4, 2006:
         Fix for an integer overflow in systrace(4)'s STRIOCREPLACE support,          Fix for an integer overflow in systrace(4)'s STRIOCREPLACE support,
         found by Chris Evans.</a>          found by Chris Evans.</a>
 <li><a href="errata.html#openssl">Oct 7, 2006:  <li><a href="errata.html#openssl">Nov 4, 2006:
         Several problems have been found in OpenSSL.</a>          Several problems have been found in OpenSSL.</a>
 <li><a href="errata.html#httpd">Oct 7, 2006:  <li><a href="errata.html#httpd">Nov 4, 2006:
         httpd(8) does not sanitize the Expect header from an HTTP request          httpd(8) does not sanitize the Expect header from an HTTP request
         when it is reflected back in an error message, which might allow          when it is reflected back in an error message, which might allow
         cross-site scripting (XSS) style attacks.</a>          cross-site scripting (XSS) style attacks.</a>

Legend:
Removed from v.1.334  
changed lines
  Added in v.1.335