Re: OpenSSL Update - not a security update???

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 03/07/2016 12:14 PM, James Washington wrote:
> Hey all,
> 
> Sorry to jump in here but out of curiosity, has the patch actually been back ported to earlier versions of OpenSSL regarding the recent DROWN attack? I've checked the RPM change log and nothing's been mentioned relating to CVE-2016-0800 (I think that was the CVE number). Or is this thread not relating to that vulnerability?
> 
> Kind regards

Yes, this update addresses Drown .. but installing the update alone is
not enough, you also have to turn off SSLv2

You can see how to do that for many different services here:

https://access.redhat.com/articles/1462183

And lots of info here:

https://access.redhat.com/security/vulnerabilities/drown

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
https://lists.centos.org/mailman/listinfo/centos

[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux