SH 4.0 vulnerabilities

"Raynard A. Jong" <[email protected]> Fri, 4 Oct 2002 14:52:57 -0700
Newsgroups gmane.linux.redhat.stronghold
Message-ID <p05100301b9c3b686ffdc@[128.115.101.2]>
I was forced to upgrade from SH 2.4.2 to SH 4.0 because fixes for the 
Linux slapper vulnerability were not available from RedHat for the 
older version of Stronghold.

So after spending my $1000 to get the latest version, what do I get? 
The CD I receive has version  Stronghold 4.0 that has the Apache HTTP 
server chunked encoding heap buffer overflow as well as the Openssl 
SSL2 master key buffer overflow.

What  a disappointment.  It doesn't say much for RedHat.  When you 
purchase a product, you should at expect that all the old, known 
vulnerabilities should be removed.