20231094 problem in UTILITY/LINKS
authorRich Burridge <rich.burridge@oracle.com>
Wed, 07 Jan 2015 08:08:47 -0800
changeset 3591 76362dc58c44
parent 3589 bdfbf7f178a7
child 3592 3149dfab6bc6
20231094 problem in UTILITY/LINKS
components/links/patches/init-openssl.patch
--- /dev/null	Thu Jan 01 00:00:00 1970 +0000
+++ b/components/links/patches/init-openssl.patch	Wed Jan 07 08:08:47 2015 -0800
@@ -0,0 +1,14 @@
+Disable SSLv2 and SSLv3 in elinks to "mitigate POODLE vulnerability".
+
+This change will be passed upstream.
+
+--- links-1.03/https.c.orig	2014-12-17 15:47:04.315785336 -0800
++++ links-1.03/https.c	2015-01-06 13:08:06.766439550 -0800
[email protected]@ -41,6 +41,7 @@
+ 		SSLeay_add_ssl_algorithms();
+ 		context = SSL_CTX_new(SSLv23_client_method());
+ 		SSL_CTX_set_options(context, SSL_OP_ALL);
++		SSL_CTX_set_options(context, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3);
+ 		SSL_CTX_set_default_verify_paths(context);
+ /* needed for systems without /dev/random, but obviously kills security. */
+ 		/*{