OpenSSL Security Update

Published: 2012-03-12
Last Updated: 2012-03-12 20:52:58 UTC
by Guy Bruneau (Version: 1)
OpenSSL has issued a security update for the CMS and S/MIME Bleichenbacher attack (CVE-2012-0884). "SSL/TLS applications are *NOT* affected by this problem since the SSL/TLS code does not use the PKCS#7 or CMS decryption code." [1]

OpenSSL 0.9.8u and OpenSSL 1.0.0h are available for download here.



Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu

