Workaround for CVE-2014-3566 (POODLE) required
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
lighttpd (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Bug Description
In order to close the recently disclosed security vulnerability in SSLv3 (CVE-2014-3566 a.k.a. POODLE), one needs to disable SSLv3 support.
According to http://
(server.c.961) WARNING: unknown config-key: ssl.use-sslv3 (ignored)
I suppose that the logical way to deal with this is to either backport the "ssl.use-sslv3" functionality to the 1.4.28 version shipped by Ubuntu 12.04.5 LTS, or to upgrade the shipped package to 1.4.29 or newer.
Tore
CVE References
information type: | Private Security → Public Security |
Changed in lighttpd (Ubuntu): | |
importance: | Undecided → Medium |
tags: | added: precise |
tags: | added: poodle |
Status changed to 'Confirmed' because the bug affects multiple users.