Subject: RE: TLS Renegotiation Vulnerability: Proof of Concept Code
(Python)
Also, can you change this:
"Transport Layer Security (TLS) Renegotiation Indication Extension, IETF
draft standard that addresses the vulnerability."
To:
"Transport Layer Security (TLS) Renegotiation Indication Extension, IETF
Also, can you change this:
"Transport Layer Security (TLS) Renegotiation Indication Extension, IETF
draft standard that addresses the vulnerability."
To:
"Transport Layer Security (TLS) Renegotiation Indication Extension, IETF TLS
Working Group draft that addresses the vulnerability."
http://www.ietf.org/rfc/rfc5746.txt
Description:
Openssl has been patched to address multiple vulnerabilities;
see the listed CVEs for details. Most importantly, this update
adds support for the TLS Renegotiation Indication Extension as
specified in RFC-5746, to address man-in-the-middle attack
weaknesses in the TLS protocol.
http://wiki.rpath.com/Advisories:rPSA-2010-0036