[[EMAIL PROTECTED] - Mon Aug 12 17:59:26 2002]:

>      This mail is regarding CERT-23 that was reported recently.
> 
>     As per the CERT, to fix the reported vulnerabilities, either we
> should
>     upgrade to version Openssl09.6.e or apply the patch from version
>     Openssl0.9.6d.

Yes.

>     In this regard, we would like to know the following,
> 
>     1.  We are using Openssl0.9.6b beta version. Is it OK if we apply
> the
>           version Openssl0.9.6d patch
> (crytlib.h,obj_dat.c,asn1_lib.c,conf_def.c ) to
>           version Openssl0.9.6b and rebuild the library (libcrypto.a).
> Will there be
>           problem in this approach.

You should achieve the same level of security as when using 0.9.6e.

>     2. Will there be any change in behaviour.

No, there should not be any changes (except for the case of an attack,
of course :-).

Best regards,
       Lutz
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to