[CentOS] OpenSSL Advisory affects Exim

Always Learning

centos at u61.u22.net
Wed Sep 7 00:09:27 UTC 2011


        OpenSSL is one of the two available implementations of the TLS
        protocol in Exim.  The other is GnuTLS.  In the output of { exim
        -bV } is a line "Support for:"; if it does not include "OpenSSL"
        then you are not affected.
        
        The OpenSSL advisory covers two issues:
         (1) CVE-2011-3207: CRL validation with expired CRLs
         (2) CVE-2011-3210: TLS ephemeral ECDH crashes
        
Read the rest at

https://lists.exim.org/lurker/message/20110906.205555.cf73e2ac.en.html


Centos 5.6 has Exim 4.63 and it has OpenSSL

Regards,

Paul.






More information about the CentOS mailing list