OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: SSL renegociation vulnerability

From: Brian Seklecki (sekleckinoc.cfi.pgh.pa.us)
Date: Fri Dec 04 2009 - 00:13:52 CST


On Thu, 2009-12-03 at 04:16 +0100, Emmanuel Dreyfus wrote:
>
> This fix is just about mod_proxy_ftp, not the whole SSL handshake bug,
> isn't it?
>

Yea I was half asleep when I posted that. Thanks for the catch.

However, I can confirm that:

  http://security.FreeBSD.org/patches/SA-09:15/ssl.patch

...applies cleanly. Just made a release build.sh on netbsd-5 with it.
I certainly wont be sleeping any better, though, knowing that this is
the work-around.

~BAS

>