logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> News & Hangout View previous topic :: View next topic
Reply to topic   Topic: OpenSSL 0.9.8n upgrade for Apache 2.2.x is available
Author
Steffen
Moderator


Joined: 15 Oct 2005
Posts: 3058
Location: Hilversum, NL, EU

PostPosted: Sat 10 Apr '10 15:14    Post subject: OpenSSL 0.9.8n upgrade for Apache 2.2.x is available Reply with quote

OpenSSL 0.9.8n has been released, it is as upgrade available at the download page www.apachelounge.com/download/

Security flaws have been fixed in OpenSSL 0.9.8n and have build it with the newest nasm.

Steffen

Changes between 0.9.8n and 0.9.8m


    *) When rejecting SSL/TLS records due to an incorrect version number, never
    update s->server with a new major version number. As of
    - OpenSSL 0.9.8m if 'short' is a 16-bit type,
    - OpenSSL 0.9.8f if 'short' is longer than 16 bits,
    the previous behavior could result in a read attempt at NULL when
    receiving specific incorrect SSL/TLS records once record payload
    protection is active. (CVE-2010-0740)
    [Bodo Moeller, Adam Langley <agl@chromium.org>]

    *) Fix for CVE-2010-0433 where some kerberos enabled versions of OpenSSL
    could be crashed if the relevant tables were not present (e.g. chrooted).
    [Tomas Hoger <thoger@redhat.com>]
Back to top
James Blond
Moderator


Joined: 19 Jan 2006
Posts: 7298
Location: Germany, Next to Hamburg

PostPosted: Thu 03 Jun '10 15:16    Post subject: Reply with quote

Hi Steffen,
can you please build 0.9.8o please?

Did you have experience with 1.0.0 ?
Back to top
admin
Site Admin


Joined: 15 Oct 2005
Posts: 679

PostPosted: Thu 03 Jun '10 19:55    Post subject: Reply with quote

Yep, planned coming weekend.

No experience yet with 1.0.0.

Steffen
Back to top
glsmith
Moderator


Joined: 16 Oct 2007
Posts: 2268
Location: Sun Diego, USA

PostPosted: Fri 04 Jun '10 4:53    Post subject: Reply with quote

I've been using 1.0.0 for at least a month with no problems seen. Since moving to 1.0.0 I have not had the server serve up the default cert for a SNI host either. I still have not figured out if that is a browser, Apache or OpenSSL problem yet nor do I expect I ever will.
Back to top


Reply to topic   Topic: OpenSSL 0.9.8n upgrade for Apache 2.2.x is available View previous topic :: View next topic
Post new topic   Forum Index -> News & Hangout