Brief update on 2.5.4 SP patch

Ian Young ian at iay.org.uk
Wed Mar 4 09:32:56 EST 2015


> On 4 Mar 2015, at 01:13, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> A possible complicating factor is whether this latest set of TLS 
> vulnerabilities end up causing an OpenSSL patch, but as long as they 
> release it soon, it won't be a problem.

For the FREAK attack, in particular, https://www.smacktls.com says:

	• OpenSSL (CVE-2015-0204): versions before 1.0.1k are vulnerable.

1.0.1k appears to have been shipped 9-Jan-2015.

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20150304/1a082564/attachment-0001.bin 


More information about the dev mailing list