ad512a613f
Fix a flaw in the OpenSSL SSL/TLS server code where an old bug workaround allows malicous clients to modify the stored session cache ciphersuite. In some cases the ciphersuite can be downgraded to a weaker one on subsequent connections. See http://www.openssl.org/news/secadv_20101202.txt (CVE-2010-4180) |
||
---|---|---|
.. | ||
libsaslc | ||
netpgp | ||
openssh | ||
openssl | ||
Makefile |