On Aug 7, 2014, at 15:07 , Alexander Bergmann <[email protected]> wrote:

> Hi OpenSSL release team,
> 
> I'm just curious if there is a CVE missing inside the OpenSSL 0.9.8 
> Branch Release notes from last night. I came across commit 
> fc4bd2f287582c5f51f9549727fd5a49e9fc3012 (CVE-2014-3511) that is not 
> listed for the 0.9.8 branch in the security advisotry or the release 
> notes. 
> 
> Is CVE-2014-3511 "TLS protocol downgrade attack" also affecting the 
> 0.9.8/1.0.0 branches?

No, because neither openssl 0.9.8 nor 1.0.0 support anything better than
TLS 1.0 in the first place.


rainer
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to