On Thu, 7 Aug 2014 15:07:44 +0200 Alexander Bergmann wrote:

> Is CVE-2014-3511 "TLS protocol downgrade attack" also affecting the 
> 0.9.8/1.0.0 branches?

The issue is described as downgrade *to* TLS 1.0, which is the highest
version supported by OpenSSL before 1.0.1.

-- 
Tomas Hoger / Red Hat Product Security
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to