Re: Time for Tomcat Native 1.2.24?

2020-04-23 Thread Michael Osipov
Am 2020-04-22 um 12:34 schrieb Mark Thomas: Hi all, You have probably seen this: OpenSSL - CVE-2020-1967 https://openssl.markmail.org/thread/nuamcatocap7rwrw I have reviewed the Tomcat Native code and confirmed that we do not call SSL_check_chain() at any point. I also looked at the OpenSSL

Re: Time for Tomcat Native 1.2.24?

2020-04-22 Thread Martin Grigorov
Hi, On Wed, Apr 22, 2020 at 1:34 PM Mark Thomas wrote: > Hi all, > > You have probably seen this: > OpenSSL - CVE-2020-1967 > https://openssl.markmail.org/thread/nuamcatocap7rwrw > > I have reviewed the Tomcat Native code and confirmed that we do not call > SSL_check_chain() at any point. > > I

Time for Tomcat Native 1.2.24?

2020-04-22 Thread Mark Thomas
Hi all, You have probably seen this: OpenSSL - CVE-2020-1967 https://openssl.markmail.org/thread/nuamcatocap7rwrw I have reviewed the Tomcat Native code and confirmed that we do not call SSL_check_chain() at any point. I also looked at the OpenSSL code as I was concerned that we might hit the