Re: CVE-2009-3555 not addressed in OpenSSL

2010-09-28 Thread Yves-Alexis Perez
On mar., 2010-09-28 at 17:58 -0500, Jordon Bedwell wrote: > On 09/28/2010 03:04 PM, Marsh Ray wrote: > > On 09/24/2010 02:45 AM, Simon Josefsson wrote: > > But that's a choice made by Debian. Call it release policy, procedure, > > or whatever, Debian cannot use the existence of its own bureaucracy

Re: CVE-2009-3555 not addressed in OpenSSL

2010-09-28 Thread Jordon Bedwell
On 09/28/2010 03:04 PM, Marsh Ray wrote: On 09/24/2010 02:45 AM, Simon Josefsson wrote: But that's a choice made by Debian. Call it release policy, procedure, or whatever, Debian cannot use the existence of its own bureaucracy as a justification for wrong action (or inaction). Microsoft has impl

Re: CVE-2009-3555 not addressed in OpenSSL

2010-09-28 Thread Marsh Ray
On 09/24/2010 02:45 AM, Simon Josefsson wrote: Marsh Ray writes: As a long-term Debian user myself, I appeal to Debian's sense of enlightened self-interest and urge that RFC 5746 support be backported to stable. FWIW, the latest stable GnuTLS version with RFC 5746 support is not even in test