Re: SSL Vulnerability

Min Min Tsan <[email protected]> Tue, 11 Mar 2003 16:02:41 +0000
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
On Mon, Mar 10, 2003 at 10:24:28AM -0600, Jeromey Hannel wrote:
> Redhat just released an updated OpenSSL packages fix timing attack 
> (Security Advisory - RHSA-2003:062-11).  After looking into this, I 
> noticed that openssl.org had also released a patch resolving this 
> issue.   
> 
> I currently run Stronghold 3.0 Build 3020.  Will there be an upgrade 
> or a patch to resolve this issue.

New packages for Stronghold 4 for other platforms have been recently 
released on 28 February 2003 to fix this issue. Please refer to the 
errata at:

http://rhn.redhat.com/errata/RHSA-2003-082.html
 
However, our engineers are currently still working on new packages for 
Stronghold 3.0 to fix the above issue and we'll be releasing a security 
advisory about this earliest by end of this week. Please note that Red 
Hat will continue to provide technical support and any critical security 
software updates for Stronghold 3 until June 30, 2003 only.

Kind regards,
Min Min
--
Red Hat Stronghold Support                   
http://stronghold.redhat.com/                
http://www.redhat.com/software/apache/stronghold/