tor disables the SSLv3 for OpenSSL 1.0.0j on Fedora
View options
- Truncate descriptions
but OpenSSL 1.0.0j have got fix for CVE-2011-4576
tor_tls_context_new(): Disabling SSLv3 because this OpenSSL version might otherwise be vulnerable to CVE-2011-4576 (compile-time version 10000003 (OpenSSL 1.0.0j-fips 10 May 2012); runtime version 10000003 (OpenSSL 1.0.0j-fips 10 May 2012))
Trac:
Username: kukabu
- Show labels
- Show closed items