Full Disclosure mailing list archives

OpenSSL problem: is mod_ssl also vulnerable?


From: full-disclosure () lists netsys com (Jedi/Sector One)
Date: Wed, 31 Jul 2002 09:13:02 +0200

On Wed, Jul 31, 2002 at 08:50:31AM +0200, Peter Bieringer wrote:
does anyone know whether mod_ssl (used with Apache 1.3) is also
vulnerable. Currently, last version seen on their webpage is 2.8.10
(24 June 2002).

  Yes, the OpenSSL vulnerability can be triggered through mod_ssl.
  
  But you don't need a new mod_ssl version to be safe against it. Only bring
OpenSSL up to date, and your mod_ssl module will be safe.

-- 
 __  /*-      Frank DENIS (Jedi/Sector One) <j () 42-Networks Com>     -*\  __
 \ '/    <a href="http://www.PureFTPd.Org/";> Secure FTP Server </a>    \' /
  \/  <a href="http://www.Jedi.Claranet.Fr/";> Misc. free software </a>  \/


Current thread: