Hello,

    I am Dhana from HP working on BIND product. My product
    uses Openssl for DNSSEC feature.

     This mail is regarding CERT-23 that was reported recently.

    As per the CERT, to fix the reported vulnerabilities, either we
should
    upgrade to version Openssl09.6.e or apply the patch from version
    Openssl0.9.6d.

    In this regard, we would like to know the following,

    1.  We are using Openssl0.9.6b beta version. Is it OK if we apply
the
          version Openssl0.9.6d patch
(crytlib.h,obj_dat.c,asn1_lib.c,conf_def.c ) to
          version Openssl0.9.6b and rebuild the library (libcrypto.a).
Will there be
          problem in this approach.

    2. Will there be any change in behaviour.

    It would be very much helpful, if you throw some information on the
    above questions.

    Thanks in advance,

--
Best Regards,
D.Dhana.

______________________________________________________________

D.DHANASEKARAN.             Tel.  : 91-80-2251554 Ext. 1403
Internet Services                  DID   : 91-80-2051403
Hewlett Packard                    Fax.  : 91-80-2283388
Software Engineering Services,     Telnet: 847-1403
30C, Cunningham Road,              Pager : 9624-252583
Bangalore - 560 052,
INDIA.                             Email : [EMAIL PROTECTED]


______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to