cwolf@hou.asp.ti.com wrote:
On the Apache web site, it recommends at least version 0.9.6e of OpenSSL and Apache-SSL HTTP Server version 1.3.27 or later.But Debian only has Apache-SSSL 1.3.26 and OpenSSL 0.9.6c in stable, and OpenSSL 0.9.6g in testing.
Debian backports security patches to the stable versions. Both apache-ssl 1.3.26.1+1.48-0woody2 and openssl 0.9.6c-2.woody.1 in woody/updates have no known security problems and are fine to use.