DROWN vulnerability in OpenSSL
The ongoing saga of OpenSSL and Solaris 10.....
So, in Solaris 10, patch 149071-19 brings the base installation of OpenSSL up to OpenSSL 1.0.1p. Now there is CVE-2016-0800, the DROWN attack, and everybody is yelling to upgrade OpenSSL to version 1.0.1s or 1.0.2g. Is there a patch for Solaris 10 that achieves this result, or otherwise deals with the DROWN attack?
Thank you in advance!
Carter