From owner-freebsd-security@FreeBSD.ORG Wed Oct 12 08:55:10 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3D92116A41F for ; Wed, 12 Oct 2005 08:55:10 +0000 (GMT) (envelope-from arne_woerner@yahoo.com) Received: from web30310.mail.mud.yahoo.com (web30310.mail.mud.yahoo.com [68.142.200.103]) by mx1.FreeBSD.org (Postfix) with SMTP id B25C343D49 for ; Wed, 12 Oct 2005 08:55:09 +0000 (GMT) (envelope-from arne_woerner@yahoo.com) Received: (qmail 42396 invoked by uid 60001); 12 Oct 2005 08:55:09 -0000 DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:Received:Date:From:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=fmvubIkO1ARTCwj5Vwtk4eDcXriRGfl08lwuXoHNlCyOdo0E4ha6te3uKGf+1RmW7NCjQcst3hqXC9b8dUdujZmneonAZM215f4WNYNxf6ku+cDHbsDh5pz9RfQYsOJfB3wN3lDve+YhkZQDRaR5+Mk01qO1T/xHx+/EquLKcfU= ; Message-ID: <20051012085509.42394.qmail@web30310.mail.mud.yahoo.com> Received: from [213.54.70.38] by web30310.mail.mud.yahoo.com via HTTP; Wed, 12 Oct 2005 01:55:08 PDT Date: Wed, 12 Oct 2005 01:55:08 -0700 (PDT) From: Arne "Wörner" To: Peter Jeremy In-Reply-To: <20051012082550.GH2482@cirb503493.alcatel.com.au> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Cc: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Oct 2005 08:55:10 -0000 --- Peter Jeremy wrote: > On Wed, 2005-Oct-12 00:12:35 -0700, Arne Wörner wrote: > >Btw: Why should the string "OpenSSL" be contained in each and > >every executable, that might use OpenSSL? > > OpenSSL has a version string of the form "OpenSSL 0.9.7e 25 Oct > 2004" embedded in it. > As far as I understand static linking, only the symbols that r used r linked into the executable... So: Why should that version string be linked into the executable? Is it a necessary part of the SSL protocol to say the version? -Arne __________________________________ Yahoo! Music Unlimited Access over 1 million songs. Try it free. http://music.yahoo.com/unlimited/