RE: CVE-2014-0224

2014-06-26 Thread Jeffrey Janner
> From: Jeffrey Janner [mailto:jeffrey.jan...@polydyne.com] > Sent: Wednesday, June 25, 2014 6:05 PM > To: 'Tomcat Users List' > Subject: CVE-2014-0224 > > Does anyone know of a way to mitigate this vulnerability until the latest > OpenSSL patch can be applied to

CVE-2014-0224

2014-06-25 Thread Jeffrey Janner
Does anyone know of a way to mitigate this vulnerability until the latest OpenSSL patch can be applied to the Native Libraries? Perhaps limiting the cipher list to the list of strongest ciphers available that are supported by the major browsers? Is there a listing somewhere of the cipher lists su