[users@httpd] Re: Apache 2.2.x and CVE-2012-2333

2012-12-25 Thread Gorkem Durgut
published on official site will be very appreciated by many users. Regards, Gorkem > > From: Gorkem Durgut >To: "users@httpd.apache.org" >Sent: Thursday, December 20, 2012 11:33 AM >Subject: Apache 2.2.x and CVE-2012-2333 > > &g

[users@httpd] Apache 2.2.x and CVE-2012-2333

2012-12-20 Thread Gorkem Durgut
Hi, I am questioning if Apache 2.2.22 with OpenSSL 0.9.8t is affected by CVE-2012-2333 (OpenSSL Invalid TLS/DTLS Record Denial of Service Vulnerability)? You may find the details of the vulnerability here: http://www.openssl.org/news/secadv_20120510.txt Here, it says that "DTLS applications a