> These patches are known to apply correctly but have not been
> thoroughly tested.

As I understand it, OpenSSL will call abort() when it detects attack
against any hole in SSL. It might be acceptable for process-per-connection
situations like Apache, but when one process serves many connections it
produces nice DoS. Yes, it's better than exploitable hole but still not
acceptable.

Arne


______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to