Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 30 Sep 2003 15:31:50 -0500
From:      "Jacques A. Vidrine" <nectar@FreeBSD.org>
To:        freebsd-security@FreeBSD.org
Subject:   OpenSSL heads-up
Message-ID:  <20030930203150.GC1996@madman.celabo.org>

next in thread | raw e-mail | index | archive | help

Hello Everyone,

You may have seen the recent announcement regarding new OpenSSL
vulnerabilities.  <URL: http://www.openssl.org/news/secadv_20030930.txt >

Just thought I'd drop a line to head off the usual questions. :-)

  Don't panic.  The vulnerability is denial-of-service.

  OpenSSL 0.9.7c will be imported into -CURRENT and -STABLE over the
  next couple of days, and included in 4.9-RELEASE.

  Fixes for the security branches will be backported and incorporated
  over the next week.

  Don't expect to see a security advisory until most or all of the
  commits have been made.

Cheers,
-- 
Jacques Vidrine   . NTT/Verio SME      . FreeBSD UNIX       . Heimdal
nectar@celabo.org . jvidrine@verio.net . nectar@freebsd.org . nectar@kth.se



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030930203150.GC1996>