tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: SSL renegociation vulnerability



Emmanuel Dreyfus wrote:
Hello

A question about the latest SSL vulnerability:
http://extendedsubset.com/?p=8

I don't have an answer to your question, but for the sake of the list archives, it should be pointed out that the ASF distributed work-around patch has been imported into pkgsrc/www/apache22 about 7 weeks ago by Matthias Scheler:

http://pkgsrc.se/files.php?messageId=20091004122135.3083A175DA%cvs.netbsd.org@localhost

As far as getting OpenSSL 0.9.8l MITM-related changes backported, I'll defer.

~BAS




Home | Main Index | Thread Index | Old Index