Brief update on 2.5.4 SP patch
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 4 09:53:31 EST 2015
On 3/4/15, 2:32 PM, "Ian Young" <ian at iay.org.uk> wrote:
>
>> On 4 Mar 2015, at 01:13, Cantor, Scott <cantor.2 at osu.edu> wrote:
>>
>> A possible complicating factor is whether this latest set of TLS
>> vulnerabilities end up causing an OpenSSL patch, but as long as they
>> release it soon, it won't be a problem.
>
>For the FREAK attack, in particular, https://www.smacktls.com says:
>
> • OpenSSL (CVE-2015-0204): versions before 1.0.1k are vulnerable.
>
>1.0.1k appears to have been shipped 9-Jan-2015.
I'm using 1.0.2. Apparently that included the fix, they just didn't talk
about it.
-- Scott
More information about the dev
mailing list