[BACK]Return to errata43.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata43.html between version 1.16 and 1.17

version 1.16, 2009/01/30 23:18:03 version 1.17, 2009/01/31 15:11:25
Line 111 
Line 111 
 <li><a name="007_openssl"></a>  <li><a name="007_openssl"></a>
 <font color="#009000"><strong>007: SECURITY FIX: January 9, 2009</strong></font> &nbsp; <i>All architectures</i><br>  <font color="#009000"><strong>007: SECURITY FIX: January 9, 2009</strong></font> &nbsp; <i>All architectures</i><br>
 The OpenSSL libraries did not correctly check the return value from  The OpenSSL libraries did not correctly check the return value from
 certain verifiction functions, allowing validation to be bypassed and  certain verification functions, allowing validation to be bypassed and
 permitting a remote attacker to conduct a "man in the middle attack"  permitting a remote attacker to conduct a "man in the middle attack"
 against SSL/TLS connections if the server is configured with a DSA or ECDSA  against SSL/TLS connections if the server is configured with a DSA or ECDSA
 certificate.  certificate.

Legend:
Removed from v.1.16  
changed lines
  Added in v.1.17