[BACK]Return to security.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/security.html between version 1.338 and 1.339

version 1.338, 2007/01/03 21:14:39 version 1.339, 2007/03/06 01:58:05
Line 233 
Line 233 
   
 <p>  <p>
 <ul>  <ul>
 <li><a href="errata.html#agp">Jan 3, 2007:  <li><a href="errata40.html#agp">Jan 3, 2007:
         Insufficient validation in vga(4) may allow an attacker to gain          Insufficient validation in vga(4) may allow an attacker to gain
         root privileges on some i386 systems.</a>          root privileges on some i386 systems.</a>
 <li><a href="errata.html#ldso">Nov 19, 2006:  <li><a href="errata40.html#ldso">Nov 19, 2006:
         ld.so(1) fails to properly sanitize the environment.</a>          ld.so(1) fails to properly sanitize the environment.</a>
 <li><a href="errata.html#systrace">Nov 4, 2006:  <li><a href="errata40.html#systrace">Nov 4, 2006:
         Fix for an integer overflow in systrace(4)'s STRIOCREPLACE support,          Fix for an integer overflow in systrace(4)'s STRIOCREPLACE support,
         found by Chris Evans.</a>          found by Chris Evans.</a>
 <li><a href="errata.html#openssl">Nov 4, 2006:  <li><a href="errata40.html#openssl">Nov 4, 2006:
         Several problems have been found in OpenSSL.</a>          Several problems have been found in OpenSSL.</a>
 <li><a href="errata.html#httpd">Nov 4, 2006:  <li><a href="errata40.html#httpd">Nov 4, 2006:
         httpd(8) does not sanitize the Expect header from an HTTP request          httpd(8) does not sanitize the Expect header from an HTTP request
         when it is reflected back in an error message, which might allow          when it is reflected back in an error message, which might allow
         cross-site scripting (XSS) style attacks.</a>          cross-site scripting (XSS) style attacks.</a>

Legend:
Removed from v.1.338  
changed lines
  Added in v.1.339