The charm leaves the server vulnerable to POODLE attack

Bug #1407732 reported by Johan Ehnberg
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
owncloud (Juju Charms Collection)
Status tracked in Precise
Precise
Fix Released
Critical
José Antonio Rey
Trusty
Fix Released
Critical
José Antonio Rey

Bug Description

Changing /etc/apache2/mods-enabled/ssl.conf
SSLProtocol All
to
SSLProtocol All -SSLv3
fixes this.

Related branches

information type: Private Security → Public
Revision history for this message
José Antonio Rey (jose) wrote :

Hello, Johan!

Be sure that I'm working on this right now. Thanks for the heads up!

Changed in owncloud (Juju Charms Collection):
status: New → Triaged
importance: Undecided → Critical
assignee: nobody → José Antonio Rey (jose)
José Antonio Rey (jose)
Changed in owncloud (Charms Trusty):
status: New → In Progress
Changed in owncloud (Charms Precise):
status: Triaged → In Progress
Changed in owncloud (Charms Trusty):
importance: Undecided → Critical
assignee: nobody → José Antonio Rey (jose)
status: In Progress → Fix Committed
José Antonio Rey (jose)
Changed in owncloud (Charms Precise):
status: In Progress → Fix Committed
Changed in owncloud (Charms Trusty):
status: Fix Committed → Fix Released
José Antonio Rey (jose)
Changed in owncloud (Charms Precise):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.