Full Disclosure mailing list archives
OpenSSL problem: is mod_ssl also vulnerable?
From: full-disclosure () lists netsys com (Jedi/Sector One)
Date: Wed, 31 Jul 2002 09:13:02 +0200
On Wed, Jul 31, 2002 at 08:50:31AM +0200, Peter Bieringer wrote:
does anyone know whether mod_ssl (used with Apache 1.3) is also vulnerable. Currently, last version seen on their webpage is 2.8.10 (24 June 2002).
Yes, the OpenSSL vulnerability can be triggered through mod_ssl. But you don't need a new mod_ssl version to be safe against it. Only bring OpenSSL up to date, and your mod_ssl module will be safe. -- __ /*- Frank DENIS (Jedi/Sector One) <j () 42-Networks Com> -*\ __ \ '/ <a href="http://www.PureFTPd.Org/"> Secure FTP Server </a> \' / \/ <a href="http://www.Jedi.Claranet.Fr/"> Misc. free software </a> \/
Current thread:
- OpenSSL problem: is mod_ssl also vulnerable? Peter Bieringer (Jul 30)
- OpenSSL problem: is mod_ssl also vulnerable? Jedi/Sector One (Jul 31)
- OpenSSL problem: is mod_ssl also vulnerable? Helmut Springer (Jul 31)
- OpenSSL problem: is mod_ssl also vulnerable? Thomas Oppel (Jul 31)
- OpenSSL problem: is mod_ssl also vulnerable? Ron DuFresne (Jul 31)
- OpenSSL problem: is mod_ssl also vulnerable? Roman Drahtmueller (Jul 31)
- OpenSSL problem: is mod_ssl also vulnerable? Ron DuFresne (Jul 31)
- OpenSSL problem: is mod_ssl also vulnerable? Jedi/Sector One (Jul 31)