Re: [users@httpd] R: [users@httpd] CVE-2013-2566

2014-01-20 Thread Yehuda Katz
an't' remember. > > Have you any suggestion in order to configure SSLCipherSuite to be > compliant to CVE-2013-2566 > > > Thanks in advance. > > > Manuela Vorazzo > > > -Messaggio originale- > Da: Eric Covener [mailto:cove...@gmail.com] >

[users@httpd] R: [users@httpd] CVE-2013-2566

2014-01-20 Thread Vorazzo Manuela
in advance. Manuela Vorazzo -Messaggio originale- Da: Eric Covener [mailto:cove...@gmail.com] Inviato: lunedì 20 gennaio 2014 13:10 A: users@httpd.apache.org Oggetto: Re: [users@httpd] CVE-2013-2566 > The RC4 algorithm, as used in the TLS protocol and SSL protocol, has > many s= ingle-by

Re: [users@httpd] CVE-2013-2566

2014-01-20 Thread Eric Covener
> The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many s= > ingle-byte biases, which makes it easier for remote attackers to conduct pl= > aintext-recovery attacks via statistical analysis of ciphertext in a large = > number of sessions that use the same plaintext. http://http

[users@httpd] CVE-2013-2566

2014-01-20 Thread Vorazzo Manuela
Hello everyone. Where can I find a list of vulnerabilies related to apache 2.2.26. I would like to know if this release bypasses the vulnerability CVE-2013-25= 66 The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many s= ingle-byte biases, which makes it easier for remo