[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2011-01-04 Thread Matthew Nuzum
** Changed in: ubuntu-website Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/566467 Title: potentially vulnerable to cve-2009-3555 -- ubuntu-bugs mailing list ubuntu

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-09-21 Thread Marc Deslauriers
Updated packages have been released for stable releases http://www.ubuntu.com/usn/usn-990-1 http://www.ubuntu.com/usn/usn-990-2 -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification because you are a member of Ubuntu Bugs, which is s

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-08-13 Thread Marc Deslauriers
@Amahdy: It is currently fixed in Maverick. Updated openssl and apache2 packages will appear in -proposed for earlier releases probably next week. See bug #616759 for tracking. -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-08-13 Thread Amahdy
Any progress for this? I heard that this bug resolution needs couple of upgrades for: Apache, mod_ssl, and openssl All the latest available versions on Ubuntu repository does not contain the resolution, this bug affects launchpad as well as everybody who uses an Ubuntu server like me... I know t

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-08-01 Thread Robert Collins
** Changed in: launchpad-foundations Status: Triaged => Won't Fix ** Description changed: + Symptoms + + Using firefox open http://wiki.ubuntu.com or https://launchpad.net and look in the error console. You will see this message: site : potentially vulnerable to cve-200

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-30 Thread Sam
$ LANGUAGE=C apt-cache policy firefox firefox: Installed: 3.6.8+build1+nobinonly-0ubuntu0.10.04.1 Candidate: 3.6.8+build1+nobinonly-0ubuntu0.10.04.1 Version table: *** 3.6.8+build1+nobinonly-0ubuntu0.10.04.1 0 500 http://archive.ubuntu.com/ubuntu/ lucid-updates/main Packages

Re: [Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-23 Thread Stuart Bishop
On Mon, Jul 19, 2010 at 10:33 PM, Robert Collins <566...@bugs.launchpad.net> wrote: > In what way is it flagged? In the error log? In the main UI? Somewhere > else? The Firefox error console (Tools -> Error Console) -- Stuart Bishop http://www.stuartbishop.net/ -- potentially vulnerable to

Re: [Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-19 Thread Robert Collins
In what way is it flagged? In the error log? In the main UI? Somewhere else? -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list u

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-19 Thread Alex Mayorga Adame
I'm here from the duplicate. FWIW these are also flagged by Firefox trunk as of today: launchpad.net : server does not support RFC 5746, see CVE-2009-3555 edge.launchpad.net : server does not support RFC 5746, see CVE-2009-3555 launchpadlibrarian.net : server does not support RFC 5746, see CVE-2009

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-16 Thread Gary Poster
** Changed in: launchpad-foundations Assignee: (unassigned) => Robert Collins (lifeless) -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bu

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-15 Thread Gary Poster
RT #40432 -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listin

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-15 Thread Gary Poster
To be clear, the problem is not the potential vulnerability--IS has assured that we are not vulnerable. The concern is that more than half of Launchpad's users are Firefox users, and we want to keep them from being concerned about Launchpad, and keep us from having to reply to security questions a

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-07-15 Thread Gary Poster
I didn't think there was a way around this yet, but https://bugzilla.mozilla.org/show_bug.cgi?id=554594#c8 seems to suggest that an update to a newer openssl will make our users no longer worried about the problem. I'm reopening the bug for Foundations and will make an RT. ** Bug watch added: Moz

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-04-23 Thread Gary Poster
LOSAs verify that LP has the patch installed. They will track further Apache updates, once the protocol change has been agreed upon and implemented. ** Changed in: launchpad-foundations Status: New => Fix Released -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-04-19 Thread Matthew Nuzum
Hi, pasting from IRC: (11:52:57 AM) jdstrand: herb, newz2000: I did that apache update, and it is not vulnerable to client initiated TLS renegotiation (11:53:18 AM) jdstrand: herb, newz2000: however, it is still vulnerable to server initiated renegotiation (11:53:40 AM) jdstrand: herb, newz2000:

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-04-19 Thread Matthew Nuzum
Hi, I can confirm that the error console does indeed say this, however it's not clear to me what the impact of this is on our systems. This issue was addressed in USN 860-1 http://www.ubuntu.com/usn/USN-860-1. Herb has stated that our systems are up to date but if the sysadmins can confirm this and

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-04-19 Thread Curtis Hovey
** Project changed: launchpad => launchpad-foundations -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubunt

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-04-19 Thread Søren Bredlund Caspersen
** Also affects: ubuntu-website Importance: Undecided Status: New -- potentially vulnerable to cve-2009-3555 https://bugs.launchpad.net/bugs/566467 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ub

[Bug 566467] Re: potentially vulnerable to cve-2009-3555

2010-04-19 Thread Rickard Närström
This is if I understand it correctly problem at those sites and not Ubuntu itself. I have assigned launchpad to this how to deal with wiki.ubuntu.com? ** Also affects: launchpad Importance: Undecided Status: New ** Changed in: ubuntu Status: New => Invalid ** This bug has been f