lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: dufresne at winternet.com (Ron DuFresne)
Subject: OpenSSL problem: is mod_ssl also vulnerable?

And since I made this request for info on another list, relating to libmm
sources, here is the answer:


yes, there is a new version of mm available on
http://www.ossp.org/pkg/lib/mm/
( Status: Stable Version:   1.2.1  (28-Jul-2002) )

The advisory is here:
http://www.openpkg.org/security/OpenPKG-SA-2002.007-mm.html


Thanks,

Ron DuFresne


On Wed, 31 Jul 2002, Thomas Oppel wrote:

> Am Mittwoch, 31. Juli 2002 09:13 schrieb Jedi/Sector One:
> > On Wed, Jul 31, 2002 at 08:50:31AM +0200, Peter Bieringer wrote:
> > > does anyone know whether mod_ssl (used with Apache 1.3) is also
> > > vulnerable. Currently, last version seen on their webpage is 2.8.10
> > > (24 June 2002).
> >
> >   Yes, the OpenSSL vulnerability can be triggered through mod_ssl.
> >
> >   But you don't need a new mod_ssl version to be safe against it. Only
> > bring OpenSSL up to date, and your mod_ssl module will be safe.
>
> And what about apache-2.0.39 with SSL enabled?
> Nothing on apache.org so far.
> apache-2.0.x includes code from the mod_ssl project I guess, right?
>
> Greetings, t.o.
> --
> Thomas Oppel
> thomas.oppel@...nfels.de
> _______________________________________________
> Full-Disclosure - We believe in it.
> Full-Disclosure@...ts.netsys.com
> http://lists.netsys.com/mailman/listinfo/full-disclosure
>

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Cutting the space budget really restores my faith in humanity.  It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation." -- Johnny Hart
	***testing, only testing, and damn good at it too!***

OK, so you're a Ph.D.  Just don't touch anything.


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ