[BACK]Return to security.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/security.html between version 1.373 and 1.374

version 1.373, 2009/04/08 02:44:22 version 1.374, 2009/04/11 23:46:45
Line 239 
Line 239 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href="errata45.html#002_pf">April 11, 2009:
           When pf attempts to perform translation on a specially
           crafted IP datagram, a null pointer dereference will occur,
           resulting in a kernel panic.</a>
 <li><a href="errata45.html#001_openssl">April 8, 2009:  <li><a href="errata45.html#001_openssl">April 8, 2009:
         OpenSSL's ASN.1 handling code could be forced to make invalid          OpenSSL's ASN.1 handling code could be forced to make invalid
         memory accesses by certain invalid strings or structures, allowing          memory accesses by certain invalid strings or structures, allowing
Line 255 
Line 259 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href="errata44.html#013_pf">April 11, 2009:
           When pf attempts to perform translation on a specially
           crafted IP datagram, a null pointer dereference will occur,
           resulting in a kernel panic.</a>
 <li><a href="errata44.html#012_openssl">April 8, 2009:  <li><a href="errata44.html#012_openssl">April 8, 2009:
         OpenSSL's ASN.1 handling code could be forced to make invalid          OpenSSL's ASN.1 handling code could be forced to make invalid
         memory accesses by certain invalid strings or structures, allowing          memory accesses by certain invalid strings or structures, allowing
Line 285 
Line 293 
   
 <p>  <p>
 <ul>  <ul>
   <li><a href="errata43.html#013_pf">April 11, 2009:
           When pf attempts to perform translation on a specially
           crafted IP datagram, a null pointer dereference will occur,
           resulting in a kernel panic.</a>
 <li><a href="errata43.html#012_openssl">April 8, 2009:  <li><a href="errata43.html#012_openssl">April 8, 2009:
         OpenSSL's ASN.1 handling code could be forced to make invalid          OpenSSL's ASN.1 handling code could be forced to make invalid
         memory accesses by certain invalid strings or structures, allowing          memory accesses by certain invalid strings or structures, allowing

Legend:
Removed from v.1.373  
changed lines
  Added in v.1.374