OpenSSL Fixed in OpenSSL 0.9.7d (Affected 0.9.7a-0.9.7c) CVE-2004-0081 (OpenSSL advisory) 17 March 2004: The Codenomicon TLS Test Tool found that some unknown message types were handled incorrectly, allowing a remote attacker to cause a denial of service (infinite loop). Reported by OpenSSL group. Fixed in OpenSSL 0.9.6d (Affected 0.9.6-0.9.6c)

OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. It is also a general-purpose cryptography library. For more information about the team and community around the project, or to start making your own contributions, start with the community page.

Is DTLS implementation available in openssl package 0.9.7a-33.24? This vulnerability (CVE-2007-4995) is part of Retina scans (performing DISA STIG and SRR review). This applies only to 0.9.8 and later, but VMWare patches funny, like correcting CVE-2007-5135 in 33.24 release (implemented in the 0.9.8f release of the mainline program).

Mar 15, 2003 · This file gives a brief overview of the major changes between each OpenSSL release. For more details please read the CHANGES file. Major changes between OpenSSL 0.9.7 and OpenSSL 0.9.7a: o Security: Important security related bugfixes. o Enhanced compatibility with MIT Kerberos. o Can be built without the ENGINE framework. o IA32 assembler

Upgrade OpenSSL/0.9.7a to 0.9.8 | cPanel Forums Sep 06, 2005 version - Difference between OpenSSL 09.8z* and 1.0.1 OpenSSL seems to actively maintain 0.9.8 series, currently in 0.9.8zc and develop 1.x series at the same time. Can someone provide authoritative set of differences between the two branches? What protocols or features 1.0.1 series has that 0.9.8-latest does not and will not?