[ANNOUNCE] mod_ssl 2.8.10
"Ralf S. Engelschall" <[email protected]> Mon, 24 Jun 2002 13:24:41 +0200
| Newsgroups | gmane.comp.apache.mod-ssl.announce |
|---|---|
| Organization | Engelschall, Germany. |
| Message-ID | <[email protected]> |
Another bugfixing round in the maintainance of mod_ssl 2.8 for Apache 1.3.
Fetch it and upgrade from:
o http://www.modssl.org/source/
o ftp://ftp.modssl.org/source/
Yours,
Ralf S. Engelschall
[email protected]
www.engelschall.com
Changes with mod_ssl 2.8.10 (19-Jun-2002 to 24-Jun-2002)
*) Fixed off-by-one buffer overflow bug in the compatibility
functionality (mapping of old directives to new ones).
*) Fixed memory leak in processing of CA certificates.
*) In case there is actually a certificate chain in the session cache,
we now use the value of SSL_get_peer_certificate(ssl) to verify as
it will have been removed from the chain before it was put in the
cache.
*) Seed the PRNG with a maximum of 1K from the internal scoreboard.
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
Official Announcement Mailing List [email protected]
Automated List Manager [email protected]