Comment 4 for bug 616759

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package apache2 - 2.2.11-2ubuntu2.7

---------------
apache2 (2.2.11-2ubuntu2.7) jaunty-security; urgency=low

  * debian/patches/909_sslinsecurerenegotiation-directive.dpatch: once
    openssl gets updated to fix CVE-2009-3555, server renegotiations with
    unpatched clients will fail. This patch adds the ability to revert to
    the previous unsafe behaviour with a new SSLInsecureRenegotiation
    directive. (LP: #616759)
  * debian/control: add specific dependency on first openssl version to get
    CVE-2009-3555 fix.
 -- Marc Deslauriers <email address hidden> Mon, 16 Aug 2010 13:34:47 -0400