Subject: openssl problem?
To: None <tech-security@netbsd.org>
From: Steven M. Bellovin <smb@cs.columbia.edu>
List: tech-security
Date: 09/14/2006 20:49:44
I believe that many versions of NetBSD are vulnerable to the attacks
described in http://www.openssl.org/news/secadv_20060905.txt -- at least,
I'm running -current from ~3 weeks ago, and it has 0.9.8b.  -current from
6 Sept seems to have the fix; I suspect that it will need to be pulled up
into all current versions.

		--Steven M. Bellovin, http://www.cs.columbia.edu/~smb