OpenSSL is one of the two available implementations of the TLS protocol in Exim. The other is GnuTLS. In the output of { exim -bV } is a line "Support for:"; if it does not include "OpenSSL" then you are not affected. The OpenSSL advisory covers two issues: (1) CVE-2011-3207: CRL validation with expired CRLs (2) CVE-2011-3210: TLS ephemeral ECDH crashes Read the rest at https://lists.exim.org/lurker/message/20110906.205555.cf73e2ac.en.html Centos 5.6 has Exim 4.63 and it has OpenSSL Regards, Paul. _______________________________________________ CentOS mailing list CentOS@xxxxxxxxxx http://lists.centos.org/mailman/listinfo/centos