# HG changeset patch # User Rich Burridge # Date 1420728914 28800 # Node ID 937319736f5cdf716c483af276d2f43277d7da32 # Parent 96f65643c9a064c0a718203300e1cde572b0f008 20231094 problem in UTILITY/LINKS diff -r 96f65643c9a0 -r 937319736f5c components/links/patches/init-openssl.patch --- /dev/null Thu Jan 01 00:00:00 1970 +0000 +++ b/components/links/patches/init-openssl.patch Thu Jan 08 06:55:14 2015 -0800 @@ -0,0 +1,14 @@ +Disable SSLv2 and SSLv3 in elinks to "mitigate POODLE vulnerability". + +This change will be passed upstream. + +--- links-1.03/https.c.orig 2014-12-17 15:47:04.315785336 -0800 ++++ links-1.03/https.c 2015-01-06 13:08:06.766439550 -0800 +@@ -41,6 +41,7 @@ + SSLeay_add_ssl_algorithms(); + context = SSL_CTX_new(SSLv23_client_method()); + SSL_CTX_set_options(context, SSL_OP_ALL); ++ SSL_CTX_set_options(context, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3); + SSL_CTX_set_default_verify_paths(context); + /* needed for systems without /dev/random, but obviously kills security. */ + /*{