On Fri, Aug 08, 2014, Henning Horst wrote:

> 
> can someone please clarify whether or not this vulnerability affects
> 1.0.1 clients which explicitly disable SRP ciphers via
> SSL_CTX_set_cipher_list?
> 

Disabling them with the cipherlist will still leave you vulnerable. One of the
bugs this fixed was that an SRP ciphersuites could be specified even if it was
not present in ClientHello.

If you disable SRP at compile time with no-srp you're OK though.

Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [email protected]

Reply via email to