[BACK]Return to security.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/security.html between version 1.280 and 1.281

version 1.280, 2004/03/30 06:00:41 version 1.281, 2004/05/05 19:36:59
Line 227 
Line 227 
   
 <p>  <p>
 <ul>  <ul>
 <li>None yet.  <li><a href=errata.html#cvs> May 5, 2004:
           Pathname validation problems have been found in cvs(1),
           allowing clients and servers access to files outside the
           repository or local CVS tree.</a>
 </ul>  </ul>
   
 <p>  <p>
Line 241 
Line 244 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href=errata34.html#cvs> May 5, 2004:
           Pathname validation problems have been found in cvs(1),
           allowing clients and servers access to files outside the
           repository or local CVS tree.</a>
 <li><a href=errata34.html#openssl> March 17, 2004:  <li><a href=errata34.html#openssl> March 17, 2004:
         A missing check for a NULL-pointer dereference may allow a          A missing check for a NULL-pointer dereference may allow a
         remote attacker to crash applications using OpenSSL.          remote attacker to crash applications using OpenSSL.</a>
 <li><a href=errata34.html#isakmpd2> March 17, 2004:  <li><a href=errata34.html#isakmpd2> March 17, 2004:
         Defects in the payload validation and processing functions of          Defects in the payload validation and processing functions of
         isakmpd have been discovered. An attacker could send malformed          isakmpd have been discovered. An attacker could send malformed
Line 281 
Line 288 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href=errata33.html#cvs> May 5, 2004:
           Pathname validation problems have been found in cvs(1),
           allowing clients and servers access to files outside the
           repository or local CVS tree.</a>
 <li><a href=errata33.html#openssl> March 17, 2004:  <li><a href=errata33.html#openssl> March 17, 2004:
         A missing check for a NULL-pointer dereference may allow a          A missing check for a NULL-pointer dereference may allow a
         remote attacker to crash applications using OpenSSL.          remote attacker to crash applications using OpenSSL.</a>
 <li><a href=errata33.html#isakmpd2> March 17, 2004:  <li><a href=errata33.html#isakmpd2> March 17, 2004:
         Defects in the payload validation and processing functions of          Defects in the payload validation and processing functions of
         isakmpd have been discovered. An attacker could send malformed          isakmpd have been discovered. An attacker could send malformed

Legend:
Removed from v.1.280  
changed lines
  Added in v.1.281