On Wed, Nov 05, 2014 at 05:07:15PM +0100, Joachim Breitner wrote: > Hi, > > > Am Mittwoch, den 05.11.2014, 16:45 +0100 schrieb Moritz Muehlenhoff: > > Package: haskell-tls > > Severity: important > > Tags: security > > > > Hi, > > openssl disabled SSLv3 for jessie since 1.0.1j-1. Shall we do the same for > > haskell-tls? > > good question. Probably yes. Did openssl disable SSLv3 completely, or > did it just removed it from the default list of accepted settings?
openssl disabled it entirely; it features a dedicated build flag for it (no-ssl3). Could you approach haskell-tls upstream for their recommendation to disable it? Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org