004: SECURITY FIX: May 22, 2002 Under certain conditions, on systems using YP with netgroups in the password database, it is possible that sshd(8) does ACL checks for the requested user name but uses the password database entry of a different user for authentication. This means that denied users might authenticate successfully while permitted users could be locked out.
005: SECURITY FIX: June 19, 2002 A buffer overflow can occur during the interpretation of chunked encoding in the http daemon, leading to possible remote crash.
006: SECURITY FIX: June 24, 2002 An (as yet) undisclosed bug exists in OpenSSH which a patch is not forthcoming for yet -- no patch exists yet! However, upgrading to OpenSSH 3.3 with the UsePrivilegeSeparation option enabled will block this problem. All users are advised to update immediately, and keep an eye out for a upcoming OpenSSH 3.4 release on Monday containing a real fix.
008: SECURITY FIX: June 26, 2002 A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd module, leading to possible remote crash or exploit.