Bug#700399: [pkg-lighttpd] Bug#700399: vulnerable to CRIME SSL attack (CVE-2012-4929)

2013-02-14 Thread Arno Töll
Hi Thijs, On 12.02.2013 16:08, Thijs Kinkhorst wrote: Do you agree on the approach? Barring any objections I'm planning to release this as a DSA after the weekend. I am by no means an expert with the SSL API, but I believe your patch to disable SSL compression looks fine (although diverging

Bug#700399: [pkg-lighttpd] Bug#700399: vulnerable to CRIME SSL attack (CVE-2012-4929)

2013-02-14 Thread Thijs Kinkhorst
Op donderdag 14 februari 2013 14:31:32 schreef Arno Töll: On 12.02.2013 16:08, Thijs Kinkhorst wrote: Do you agree on the approach? Barring any objections I'm planning to release this as a DSA after the weekend. I am by no means an expert with the SSL API, but I believe your patch to