[users@httpd] Re: Apache 2.2.x and CVE-2012-2333

2012-12-25 Thread Gorkem Durgut
on official site will be very appreciated by many users. Regards, Gorkem From: Gorkem Durgut gorkem...@yahoo.com To: users@httpd.apache.org users@httpd.apache.org Sent: Thursday, December 20, 2012 11:33 AM Subject: Apache 2.2.x and CVE-2012-2333 Hi, I am

[users@httpd] Apache 2.2.x and CVE-2012-2333

2012-12-20 Thread Gorkem Durgut
Hi, I am questioning if Apache 2.2.22 with OpenSSL 0.9.8t is affected by CVE-2012-2333 (OpenSSL Invalid TLS/DTLS Record Denial of Service Vulnerability)? You may find the details of the vulnerability here: http://www.openssl.org/news/secadv_20120510.txt Here, it says that DTLS applications