_______________________________________________________________________
Package : apache
Date : November 8, 2009
Affected: 2009.0, 2009.1, 2010.0, Corporate 3.0, Corporate 4.0,
Enterprise Server 5.0, Multi Network Firewall 2.0
_______________________________________________________________________
Problem Description:
A vulnerability was discovered and corrected in apache:
Apache is affected by SSL injection or man-in-the-middle attacks
due to a design flaw in the SSL and/or TLS protocols. A short term
solution was released Sat Nov 07 2009 by the ASF team to mitigate
these problems. Apache will now reject in-session renegotiation
(CVE-2009-3555).
Additionally the SNI patch was upgraded for 2009.0/MES5 and 2009.1.
This update provides a solution to this vulnerability.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-3555
http://marc.info/?l=apache-httpd-announ ... 724966&w=2
_______________________________________________________________________