A new update is available for Fedora Core - [SECURITY] Fedora Core 3 Update: openssl096b-0.9.6b-21.2. Here the announcement:
Fedora Update Notification
FEDORA-2005-985
2005-10-13
---------------------------------------------------------------------
Product : Fedora Core 3
Name : openssl096b
Version : 0.9.6b
Release : 21.2
Summary : The OpenSSL toolkit.
Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.
---------------------------------------------------------------------
* Thu Oct 6 2005 Tomas Mraz <tmraz@redhat.com> 0.9.6b-21.2
- fix CAN-2005-2969 - remove SSL_OP_MSIE_SSLV2_RSA_PADDING which
disables the countermeasure against man in the middle attack in SSLv2
(#169863)
- more fixes for constant time/memory access for DSA signature algorithm
- replaced add-luna patch with new one with right license (#158061)
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
a81510ddd8127092def521888a29735c SRPMS/openssl096b-0.9.6b-21.2.src.rpm
a16e20e80018c7676260339fd9d5dec1 x86_64/openssl096b-0.9.6b-21.2.x86_64.rpm
fa00e72e190651d0c6c28bb197c15661 x86_64/debug/openssl096b-debuginfo-0.9.6b-21.2.x86_64.rpm
515e5aa803873859c235d0822ab74710 x86_64/openssl096b-0.9.6b-21.2.i386.rpm
515e5aa803873859c235d0822ab74710 i386/openssl096b-0.9.6b-21.2.i386.rpm
d892c00a0272ede0a0f625f5ae746313 i386/debug/openssl096b-debuginfo-0.9.6b-21.2.i386.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.