#26415 [Asn->Csd]: OpenSSL 0.9.7b is vulnerable

From: Date: Sat, 03 Jan 2004 23:26:30 +0000
Subject: #26415 [Asn->Csd]: OpenSSL 0.9.7b is vulnerable
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-52763@lists.php.net to get a copy of this message
 ID:               26415
 Updated by:       edink@php.net
 Reported By:      dietrich dot ayala at foundstone dot com
-Status:           Assigned
+Status:           Closed
 Bug Type:         OpenSSL related
 Operating System: win32
 PHP Version:      4.3.4
 Assigned To:      edink
 New Comment:

Finally, I managed to find some time to upgrade openssl. The version
bundled with the snaps and releases from now on is OpenSSL-0.9.7c.


Previous Comments:
------------------------------------------------------------------------

[2003-12-03 13:43:07] dietrich dot ayala at foundstone dot com

Hi Edin,

Is there any ETA on this? I've tried using the new DLLs but they don't
work. Wez said the function signatures may have changed.

Thanks!

Dietrich

------------------------------------------------------------------------

[2003-11-27 11:45:44] sniper@php.net

Edin, take care.. :)


------------------------------------------------------------------------

[2003-11-25 20:18:18] dietrich dot ayala at foundstone dot com

Description:
------------
the version of openssl shipped w/ php is has known vulnerabilities. php
should be updated to the latest version of openssl (0.9.7c).

http://www.openssl.org/news/secadv_20030930.txt

thanks,

dietrich




------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=26415&edit=1


Thread (9 messages)

« previous php.bugs (#52763) next »