[ANNOUNCE] mod_ssl 2.8.18
"Ralf S. Engelschall" <[email protected]> Thu, 27 May 2004 15:21:37 +0200
| Newsgroups | gmane.comp.apache.mod-ssl.announce |
|---|---|
| Organization | Engelschall, Germany. |
| Message-ID | <20040527132137.GA88148__48508.4431399175$1085664452@engelschall.com> |
A security issue was discovered.
It is now fixed with mod_ssl 2.8.18.
Please upgrade your installations ASAP.
o http://www.modssl.org/source/
o ftp://ftp.modssl.org/source/
Ralf S. Engelschall
[email protected]
www.engelschall.com
Changes with mod_ssl 2.8.18 (11-May-2004 to 27-May-2004)
*) Fix buffer overflow in "SSLOptions +FakeBasicAuth" implementation
if the Subject-DN in the client certificate exceeds 6KB in length.
(CVE CAN-2004-0488).
*) Handle the case of OpenSSL retry requests after interrupted system
calls during the SSL handshake phase.
*) Remove some unused functions.
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
Official Announcement Mailing List [email protected]
Automated List Manager [email protected]