Brief update on 2.5.4 SP patch
Ian Young
ian at iay.org.uk
Wed Mar 4 09:32:56 EST 2015
> On 4 Mar 2015, at 01:13, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> A possible complicating factor is whether this latest set of TLS
> vulnerabilities end up causing an OpenSSL patch, but as long as they
> release it soon, it won't be a problem.
For the FREAK attack, in particular, https://www.smacktls.com says:
• OpenSSL (CVE-2015-0204): versions before 1.0.1k are vulnerable.
1.0.1k appears to have been shipped 9-Jan-2015.
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20150304/1a082564/attachment-0001.bin
More information about the dev
mailing list