Brief update on 2.5.4 SP patch

Cantor, Scott cantor.2 at osu.edu
Wed Mar 4 09:53:31 EST 2015


On 3/4/15, 2:32 PM, "Ian Young" <ian at iay.org.uk> wrote:



>
>> On 4 Mar 2015, at 01:13, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> 
>> A possible complicating factor is whether this latest set of TLS 
>> vulnerabilities end up causing an OpenSSL patch, but as long as they 
>> release it soon, it won't be a problem.
>
>For the FREAK attack, in particular, https://www.smacktls.com says:
>
>	• OpenSSL (CVE-2015-0204): versions before 1.0.1k are vulnerable.
>
>1.0.1k appears to have been shipped 9-Jan-2015.

I'm using 1.0.2. Apparently that included the fix, they just didn't talk 
about it.

-- Scott



More information about the dev mailing list