Oracle Solaris System Administration (MOSC)

MOSC Banner

DROWN vulnerability in OpenSSL

edited Mar 12, 2016 4:03AM in Oracle Solaris System Administration (MOSC) 5 commentsAnswered

The ongoing saga of OpenSSL and Solaris 10.....

So, in Solaris 10, patch 149071-19 brings the base installation of OpenSSL up to OpenSSL 1.0.1p.   Now there is CVE-2016-0800, the DROWN attack, and everybody is yelling to upgrade OpenSSL to version 1.0.1s or 1.0.2g.  Is there a patch for Solaris 10 that achieves this result, or otherwise deals with the DROWN attack?

Thank you in advance!

Carter

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center