OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Problems with OpenSSL 1.0.1c - WAS: Re: ssl errors in log. error on remote or local side?

From: Charles Marcus (CMarcusMedia-Brokers.com)
Date: Sun Jun 02 2013 - 10:54:23 CDT


On 2013-05-31 7:46 AM, Charles Marcus <CMarcusMedia-Brokers.com> wrote:
> On 2013-05-22 1:45 PM, Quanah Gibson-Mount <quanahzimbra.com> wrote:
>> I would read the CHANGES file shipped with OpenSSL. They didn't
>> document the changes between 1.0.1d and 1.0.1e, but you can see the
>> changes between 1.0.1c and 1.0.1d.
>
> I read them, but nothing jumped out at me (didn't see anything
> significant warranting a charge of 'serious problems')...
>
> The gentoo version of 1.0.1c currently applies the following patches
> (not sure if these names will mean anything to anyone here or not):
>
> 1.0.0a-ldflags.patch #327421
> 1.0.0d-fbsd-amd64.patch #363089
> 1.0.0d-windres.patch #373743
> 1.0.0h-pkg-config.patch
> 1.0.1-parallel-build.patch
> 1.0.1-x32.patch
> 1.0.1-ipv6.patch

So... any specific pointers to links describing these supposed
'*serious* problems' inherent to openssl 1.0.1c?

If this is true, it shouldn't be all that difficult to provide such (and
the burden of proof is on the claimant, no?)...

--

Best regards,

Charles