On Aug 7, 2014, at 15:07 , Alexander Bergmann <[email protected]> wrote:
> Hi OpenSSL release team, > > I'm just curious if there is a CVE missing inside the OpenSSL 0.9.8 > Branch Release notes from last night. I came across commit > fc4bd2f287582c5f51f9549727fd5a49e9fc3012 (CVE-2014-3511) that is not > listed for the 0.9.8 branch in the security advisotry or the release > notes. > > Is CVE-2014-3511 "TLS protocol downgrade attack" also affecting the > 0.9.8/1.0.0 branches? No, because neither openssl 0.9.8 nor 1.0.0 support anything better than TLS 1.0 in the first place. rainer ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected]
