httpd-bugs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject DO NOT REPLY [Bug 47055] SSLVerifyClient + Directory doesn't use cache sessions
Date Mon, 09 Nov 2009 16:28:23 GMT
https://issues.apache.org/bugzilla/show_bug.cgi?id=47055

--- Comment #42 from Ruediger Pluem <rpluem@apache.org> 2009-11-09 09:28:23 CET ---
(In reply to comment #41)
> Joe, does config from first comment is vulnerabile to CVE-2009-3555?

Yes it is. Even with the patch applied. You can only "fix" it with openssl
0.9.8l, but as soon as you use 0.9.8l this config will stop working at all.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe@httpd.apache.org
For additional commands, e-mail: bugs-help@httpd.apache.org


Mime
View raw message