version 1.338, 2007/01/03 21:14:39 |
version 1.339, 2007/03/06 01:58:05 |
|
|
|
|
<p> |
<p> |
<ul> |
<ul> |
<li><a href="errata.html#agp">Jan 3, 2007: |
<li><a href="errata40.html#agp">Jan 3, 2007: |
Insufficient validation in vga(4) may allow an attacker to gain |
Insufficient validation in vga(4) may allow an attacker to gain |
root privileges on some i386 systems.</a> |
root privileges on some i386 systems.</a> |
<li><a href="errata.html#ldso">Nov 19, 2006: |
<li><a href="errata40.html#ldso">Nov 19, 2006: |
ld.so(1) fails to properly sanitize the environment.</a> |
ld.so(1) fails to properly sanitize the environment.</a> |
<li><a href="errata.html#systrace">Nov 4, 2006: |
<li><a href="errata40.html#systrace">Nov 4, 2006: |
Fix for an integer overflow in systrace(4)'s STRIOCREPLACE support, |
Fix for an integer overflow in systrace(4)'s STRIOCREPLACE support, |
found by Chris Evans.</a> |
found by Chris Evans.</a> |
<li><a href="errata.html#openssl">Nov 4, 2006: |
<li><a href="errata40.html#openssl">Nov 4, 2006: |
Several problems have been found in OpenSSL.</a> |
Several problems have been found in OpenSSL.</a> |
<li><a href="errata.html#httpd">Nov 4, 2006: |
<li><a href="errata40.html#httpd">Nov 4, 2006: |
httpd(8) does not sanitize the Expect header from an HTTP request |
httpd(8) does not sanitize the Expect header from an HTTP request |
when it is reflected back in an error message, which might allow |
when it is reflected back in an error message, which might allow |
cross-site scripting (XSS) style attacks.</a> |
cross-site scripting (XSS) style attacks.</a> |