[tor-bugs] #7070 [Tor]: tor disables the SSLv3 for OpenSSL 1.0.0j

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Tue Oct 9 07:56:01 UTC 2012


#7070: tor disables the SSLv3 for OpenSSL 1.0.0j
--------------------+-------------------------------------------------------
 Reporter:  kukabu  |          Owner:       
     Type:  defect  |         Status:  new  
 Priority:  normal  |      Milestone:       
Component:  Tor     |        Version:       
 Keywords:          |         Parent:  #4822
   Points:          |   Actualpoints:       
--------------------+-------------------------------------------------------
 but OpenSSL 1.0.0j have got fix for CVE-2011-4576

 tor_tls_context_new(): Disabling SSLv3 because this OpenSSL version might
 otherwise be vulnerable to CVE-2011-4576 (compile-time version 10000003
 (OpenSSL 1.0.0j-fips 10 May 2012); runtime version 10000003 (OpenSSL 1.0
 .0j-fips 10 May 2012))

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7070>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list