| Summary: | The POODLE also bites Konqueror | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Bjarne Thomsen <bjarne.thomsen> |
| Component: | RPM Packages | Assignee: | KDE maintainers <kde> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | minor | ||
| Priority: | Normal | CC: | mageia |
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA5TOO, MGA4TOO | ||
| Source RPM: | kdebase4-4.14.3-1.mga5.src.rpm | CVE: | |
| Status comment: | |||
|
Description
Bjarne Thomsen
2014-12-20 10:44:33 CET
The same is true for konqueror in current cauldron. Source RPM:
konqueror-4.12.5-1.1.mga4 =>
konqueror-4.12.5-1.1.mga4,konqueror-4.14.3-1.mga5 and chromium-browser-stable-39.0.2171.65-1.mga4 has SSLv3 enabled Only firefox has disabled SSLv3. Not true. epiphany-3.14.2-1.mga5 has also disabled SSLv3. Thanks for the report. This is a very minor issue, so we won't necessarily make an update for it for Mageia 4, but I'd like to get as many of these issues fixed in Mageia 5 prior to the release as possible. It affects a lot of packages, and a lot more than just web browsers, and fixes for various packages have been trickling out the past couple months, and we've updated all of them in Cauldron that I was aware of. Do you happen to know how a user can manually disable SSLv3 in Konqueror? It would be good to have that documented here. I'll assign/CC the KDE team. I'm not sure what KDE upstream's plans are for this. Let's keep this bug about Konqueror. As for Chromium, upstream plans to disable SSLv3 in version 40, which should be available in the next month if I understand correctly. Thanks for the feedback about Epiphany, as that allowed me to close a bug about that one that someone else had reported. Hardware:
i586 =>
All
Samuel Verschelde
2015-05-21 11:43:52 CEST
Component:
RPM Packages =>
Security
David Walser
2015-05-22 18:34:12 CEST
Component:
Security =>
RPM Packages
Luc Menut
2016-08-25 16:47:38 CEST
Assignee:
lmenut =>
kde just tested on cauldrons's konqueror and www.ssllabs.com told me that the user agent is not vulnerable. => closing Status:
NEW =>
RESOLVED |