Bug#136801: [firstname.lastname@example.org: Apache-SSL 1.3.22+1.47 - update to security fix]
----- Forwarded message from Ben Laurie <email@example.com> -----
Date: Mon, 04 Mar 2002 14:47:51 +0000
From: Ben Laurie <firstname.lastname@example.org>
To: Apache SSL <email@example.com>,
Apache SSL Announce <firstname.lastname@example.org>,
CERT Coordination Center <email@example.com>
Subject: Apache-SSL 1.3.22+1.47 - update to security fix
On Friday 1st March 2002 I released a security alert for Apache-SSL,
announcing a fix to a buffer overflow. Unfortunately, because the fix
had to be released in haste (since I had not been alerted before public
disclosure), the fix had a bug.
Fortunately, the bug did not leave Apache-SSL vulnerable, but it did
prevent correct operation.
I have, therefore, released an updated version of Apache-SSL today,
1.3.22+1.47, which is available from all the usual places.
Users of versions prior to this should upgrade immediately.
"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff
----- End forwarded message -----