Re: Security Vulnerability issue in openssl 9.8 version

2009-06-03 Thread tensy joseph
Customer are started asking me for this fix . So i need to release an immediate release of openssl with this fix . Not sure whether they are using DTLS . If any customer ask for the fix , i need to release the fix immediately (business policy). The patch which i have applied is this(for openssl 9.

Re: Security Vulnerability issue in openssl 9.8 version

2009-06-02 Thread Victor Duchovni
On Tue, Jun 02, 2009 at 12:33:46AM -0700, rajanchittil wrote: > > Hi All, > > Recently i got a security vulnerability issue alert reported in > http://www.vupen.com/english/advisories/2009/1377. Are you using DTLS? If you application is not using DTLS (very few are), you don't need to patch an

Re: Security Vulnerability issue in openssl 9.8 version

2009-06-02 Thread tensy joseph
I have used the following patch for this vulnerability issue http://cvs.openssl.org/chngview?cn=18187 http://cvs.openssl.org/chngview?cn=18206 http://cvs.openssl.org/chngview?cn=18154 Is this is the correct patch which solve the vulnerability issue in openssl 0.9.8h and openssl 0.9.8k Please h