[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: CVE-2009-3555 not addressed in OpenSSL



Hi Kurt,

On Thursday 11 November 2010 19:43:33 Kurt Roeckx wrote:
> So I've prepared a package based on the ubuntu patch.  I also went
> over every commit between the 0.9.8l and 0.9.8m release and am
> reasonly confident this patch should work properly.
> 
> The current package is available at:
> http://people.debian.org/~kroeckx/openssl/rfc5746/
> 
> I would welcome people testing it.  Note that it might still
> change based on feedback from people.

I have tested it in some different environments with different types of 
configurations and the packages work very fine for me.

In case someone else also wants to test them in an i386 context, the builds I 
used are here: http://people.debian.org/~thijs/openssl/

I hope we can see this update in the next point release.


Cheers,
Thijs

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: