Re: OpenSSL CVE-2009-4355

2010-04-27 Thread Brian A. Seklecki
On 1/20/2010 2:56 PM, Brian A. Seklecki wrote: Per Daniele Sluijters's inquiry on the 15th,CVE-2009-4355, as well as with a provision/draft fix for CVE-2009-3555 MITM/Renegotiation Venerability. All: Did anyone ever come to a finding on CVE-2009-4355? Using the comments in R

Re: OpenSSL CVE-2009-4355

2010-04-27 Thread Brian A. Seklecki (CFI NOC)
On 1/20/2010 2:56 PM, Brian A. Seklecki wrote: Per Daniele Sluijters's inquiry on the 15th,CVE-2009-4355, as well as with a provision/draft fix for CVE-2009-3555 MITM/Renegotiation Venerability. All: Did anyone ever come to a finding on CVE-2009-4355? Using the comments in R

[Fwd: OpenSSL 1.0.0 beta5 release]

2010-01-20 Thread Brian A. Seklecki
All: Per Daniele Sluijters's inquiry on the 15th,CVE-2009-4355, as well as with a provision/draft fix for CVE-2009-3555 MITM/Renegotiation Venerability. I suspect we wont have a patch out for RELENG_6_3 by the 31st? But I'm willing to maintain one for another few months. ~BAS -

[Fwd: OpenSSL 1.0.0 beta5 release]

2010-01-20 Thread Brian A. Seklecki
All: Per Daniele Sluijters's inquiry on the 15th,CVE-2009-4355, as well as with a provision/draft fix for CVE-2009-3555 MITM/Renegotiation Venerability. I suspect we wont have a patch out for RELENG_6_3 by the 31st? But I'm willing to maintain one for another few months. ~BAS -

Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-07:04.file

2007-05-23 Thread Brian A. Seklecki
. References > > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1536 > > The latest revision of this advisory is available at > http://security.FreeBSD.org/advisories/FreeBSD-SA-07:04.file.asc > -BEGIN PGP SIGNATURE- > Version: GnuPG v1.4.7 (FreeBSD) > > iD8D