Re: [SECURITY] [DSA 253-1] New OpenSSL packages fix timing-based attack vulnerability

2003-02-25 Thread Matt Zimmerman
On Mon, Feb 24, 2003 at 07:41:20PM -0500, Raymond Wood wrote: > > For the unstable distribution (sid) this problem has been fixed in > > version 0.9.7a-1. > > > > We recommend that you upgrade your openssl packages. > [snip] > > On sid/unstable, I have installed all the recommended patches, > in

Re: [SECURITY] [DSA 253-1] New OpenSSL packages fix timing-based attack vulnerability

2003-02-25 Thread Matt Zimmerman
On Mon, Feb 24, 2003 at 07:41:20PM -0500, Raymond Wood wrote: > > For the unstable distribution (sid) this problem has been fixed in > > version 0.9.7a-1. > > > > We recommend that you upgrade your openssl packages. > [snip] > > On sid/unstable, I have installed all the recommended patches, > in

Re: [SECURITY] [DSA 253-1] New OpenSSL packages fix timing-based attack vulnerability

2003-02-25 Thread Adrian 'Dagurashibanipal' von Bidder
On Mon, 2003-02-24 at 15:00, Martin Schulze wrote: > For the old stable distribution (potato) this problem has been fixed > in version 0.9.6c-0.potato.5. Please note that this updates the > version from potato-proposed-updates that superseds the version in > potato. Hmm. Now that a date is being

Re: [SECURITY] [DSA 253-1] New OpenSSL packages fix timing-based attack vulnerability

2003-02-24 Thread Raymond Wood
On Mon, Feb 24, 2003 at 03:00:47PM +0100, Martin Schulze imagined: > -- > Debian Security Advisory DSA 253-1 [EMAIL PROTECTED] > http://www.debian.org/security/ Martin Schulze > F

Re: [SECURITY] [DSA 253-1] New OpenSSL packages fix timing-based attack vulnerability

2003-02-24 Thread Raymond Wood
On Mon, Feb 24, 2003 at 03:00:47PM +0100, Martin Schulze imagined: > -- > Debian Security Advisory DSA 253-1 [EMAIL PROTECTED] > http://www.debian.org/security/ Martin Schulze > F