Slackware: mod_ssl timing based attack vulnerability
Summary
Here are the details from the Slackware 9.0 ChangeLog: Tue May 20 20:13:09 PDT 2003 patches/packages/mod_ssl-2.8.14_1.3.27-i386-1.tgz: Upgraded to mod_ssl-2.8.14_1.3.27. Includes RSA blinding fixes. (* Security fix *) WHERE TO FIND THE NEW PACKAGES: Updated package for Slackware 9.0: MD5 SIGNATURES: Slackware 9.0 package: 2888ecec5e2116be81b5295fc477869b mod_ssl-2.8.14_1.3.27-i386-1.tgz INSTALLATION INSTRUCTIONS: First, shut down your web server: # apachectl stop Then upgrade using upgradepkg (as root): upgradepkg mod_ssl-2.8.14_1.3.27-i386-1.tgz Finally, restart secure web services: # apachectl startssl Slackware Linux Security Team slackware security@slackware.com
Where Find New Packages
MD5 Signatures
Installation Instructions