Re: SSL Vulnerability

Andreas Deller <[email protected]> Mon, 24 Mar 2003 08:41:11 +0100 (MET)
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
Hi Min Min

I've seen that a new build (3021) is out for stronghold. Can you tell me if
there's already an IDEA-enabled build out, too?

Best regards,
	Andy Deller, Ergon Informatik AG

> From: Min Min Tsan <[email protected]>
> To: [email protected],
> 	Jeromey Hannel <[email protected]>
> Subject: Re: SSL Vulnerability
> 
> On Mon, Mar 10, 2003 at 10:24:28AM -0600, Jeromey Hannel wrote:
> > Redhat just released an updated OpenSSL packages fix timing attack 
> > (Security Advisory - RHSA-2003:062-11).  After looking into this, I 
> > noticed that openssl.org had also released a patch resolving this 
> > issue.   
> > 
> > I currently run Stronghold 3.0 Build 3020.  Will there be an upgrade 
> > or a patch to resolve this issue.
> 
> New packages for Stronghold 4 for other platforms have been recently 
> released on 28 February 2003 to fix this issue. Please refer to the 
> errata at:
> 
> http://rhn.redhat.com/errata/RHSA-2003-082.html
>  
> However, our engineers are currently still working on new packages for 
> Stronghold 3.0 to fix the above issue and we'll be releasing a security 
> advisory about this earliest by end of this week. Please note that Red 
> Hat will continue to provide technical support and any critical security 
> software updates for Stronghold 3 until June 30, 2003 only.
> 
> Kind regards,
> Min Min
> --
> Red Hat Stronghold Support                   
> http://stronghold.redhat.com/                
> http://www.redhat.com/software/apache/stronghold/