OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: SSL renegociation vulnerability

From: Emmanuel Dreyfus (manunetbsd.org)
Date: Wed Dec 02 2009 - 21:16:32 CST


Brian A. Seklecki (CFI NOC) <sekleckinoc.cfi.pgh.pa.us> wrote:

> I don't have an answer to your question, but for the sake of the list
> archives, it should be pointed out that the ASF distributed work-around
> patch has been imported into pkgsrc/www/apache22 about 7 weeks ago by
> Matthias Scheler:
>
> http://pkgsrc.se/files.php?messageId=20091004122135.3083A175DAcvs.netbsd.org

This fix is just about mod_proxy_ftp, not the whole SSL handshake bug,
isn't it?

--
Emmanuel Dreyfus
http://hcpnet.free.fr/pubz
manunetbsd.org