freebsd-ports/www/apache20
Clement Laforet 310abe64ef - Yet Another Security Fix
Fix CAN-2004-0885:

  * modules/ssl/ssl_engine_kernel.c (ssl_hook_Access): Ensure that a
  correct cipher suite has been negotiated, else deny access.

  * modules/ssl/ssl_engine_init.c (ssl_init_ctx_protocol): With OpenSSL
  0.9.7, prevent session resumption during a renegotiation to force the
  client to negotiate a new (and acceptable) cipher suite.

Credits:	Hartmut Keil, Joe Orton
2004-10-13 09:17:38 +00:00
..
files - Yet Another Security Fix 2004-10-13 09:17:38 +00:00
distinfo - Update to 2.0.52 2004-10-12 08:27:40 +00:00
Makefile - Yet Another Security Fix 2004-10-13 09:17:38 +00:00
Makefile.doc - Update to 2.0.52 2004-10-12 08:27:40 +00:00
Makefile.modules - Update to 2.0.52 2004-10-12 08:27:40 +00:00
Makefile.modules.3rd - Update to 2.0.52 2004-10-12 08:27:40 +00:00
pkg-descr - Sync pkg-descr with reality. 2004-06-05 13:52:20 +00:00
pkg-install - Fix install when people use a different /bin/sh 2004-04-07 14:27:47 +00:00
pkg-message - Update to 2.0.50 2004-07-01 05:54:56 +00:00
pkg-plist - Update to 2.0.52 2004-10-12 08:27:40 +00:00