[[EMAIL PROTECTED] - Mon Aug 12 17:59:26 2002]:
> This mail is regarding CERT-23 that was reported recently.
>
> As per the CERT, to fix the reported vulnerabilities, either we
> should
> upgrade to version Openssl09.6.e or apply the patch from version
> Openssl0.9.6d.
Yes.
> In this regard, we would like to know the following,
>
> 1. We are using Openssl0.9.6b beta version. Is it OK if we apply
> the
> version Openssl0.9.6d patch
> (crytlib.h,obj_dat.c,asn1_lib.c,conf_def.c ) to
> version Openssl0.9.6b and rebuild the library (libcrypto.a).
> Will there be
> problem in this approach.
You should achieve the same level of security as when using 0.9.6e.
> 2. Will there be any change in behaviour.
No, there should not be any changes (except for the case of an attack,
of course :-).
Best regards,
Lutz
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]