005: SECURITY FIX: June 19, 2002 A buffer overflow can occur during the interpretation of chunked encoding in the http daemon, leading to possible remote crash.
006: SECURITY FIX: June 24, 2002 An (as yet) undisclosed bug exists in OpenSSH which a patch is not forthcoming for yet -- no patch exists yet! However, upgrading to OpenSSH 3.3 with the UsePrivilegeSeparation option enabled will block this problem. All users are advised to update immediately, and keep an eye out for a upcoming OpenSSH 3.4 release on Monday containing a real fix.
008: SECURITY FIX: June 26, 2002 A buffer overflow can occur in the .htaccess parsing code in mod_ssl httpd module, leading to possible remote crash or exploit.
013: SECURITY FIX: July 30, 2002 Several remote buffer overflows can occur in the SSL2 server and SSL3 client of the ssl(8) library, as in the ASN.1 parser code in the crypto(3) library, all of them being potentially remotely exploitable.
012: SECURITY FIX: July 29, 2002 A buffer overflow can occur in the xdr_array(3) RPC code, leading to possible remote crash.
011: SECURITY FIX: July 29, 2002 A race condition exists in the pppd(8) daemon which may cause it to alter the file permissions of an arbitrary file.