SH 4.0 vulnerabilities
"Raynard A. Jong" <[email protected]> Fri, 4 Oct 2002 14:52:57 -0700
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <p05100301b9c3b686ffdc@[128.115.101.2]> |
I was forced to upgrade from SH 2.4.2 to SH 4.0 because fixes for the Linux slapper vulnerability were not available from RedHat for the older version of Stronghold. So after spending my $1000 to get the latest version, what do I get? The CD I receive has version Stronghold 4.0 that has the Apache HTTP server chunked encoding heap buffer overflow as well as the Openssl SSL2 master key buffer overflow. What a disappointment. It doesn't say much for RedHat. When you purchase a product, you should at expect that all the old, known vulnerabilities should be removed.