RE: patch available for CVE-2010-5298?

2014-04-25 Thread Lowe, Geoff
I believe Ben Laurie committed the fix on April 23rd: diff --git a/ssl/s3_pkt.c b/ssl/s3_pkt.c index 96ba632..8deeab3 100644 --- a/ssl/s3_pkt.c +++ b/ssl/s3_pkt.c @@ -1055,7 +1055,7 @@ start: { s-rstate=SSL_ST_READ_HEADER;

patch available for CVE-2010-5298?

2014-04-24 Thread Bin Lu
Thanks!

Re: patch available for CVE-2010-5298?

2014-04-24 Thread Jeffrey Walton
On Thu, Apr 24, 2014 at 1:49 PM, Bin Lu b...@juniper.net wrote: Thanks! Ben Laurire checked it in recently (within the last week or so). Until it makes it way into the the tar balls, I believe you should try: https://rt.openssl.org/Ticket/Display.html?id=2167user=guestpass=guest. Jeff