Bug#678998: libpython3.1: python3.1 disables workaround for CVE-2011-3389 (#678998)

2012-06-25 Thread Henri Salo
What is status of this issue? Is there something I can do to help? - Henri Salo -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#678998: libpython3.1: python3.1 disables workaround for CVE-2011-3389

2012-06-25 Thread Yves-Alexis Perez
Package: libpython3.1 Version: 3.1.3-1 Severity: important Hey, it seems that python3.1 is somehow vulnerable to CVE-2011-3389 (the so-called BEAST attack) since it'll by default disable the workaround provided by OpenSSL. This is fixed starting 3.1.5, according to http://www.python.org/download/