[pkg-lighttpd] Bug#765702: lighttpd: Disable SSL 3.0

Christian Tacke Christian.Tacke+debian.org at cosmokey.com
Fri Oct 17 12:39:52 UTC 2014


Package: lighttpd
Version: 1.4.31-4+deb7u3
Tags: patch

Hi,

looking at CVE-2014-3566 ("POODLE") it seems a very good
idea to finally disable SSL 3.0 by default ("secure by
default"). Please test attached patch.

Cheers

Christian Tacke

-- 
www.cosmokey.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: disable-ssl3.diff
Type: text/x-diff
Size: 332 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-lighttpd-maintainers/attachments/20141017/7e6d8ac1/attachment.diff>


More information about the pkg-lighttpd-maintainers mailing list