A new update is available for Fedora Core - [SECURITY] Fedora Core 3 Update: openssl-0.9.7a-42.2. Here the announcement:
Fedora Update Notification
FEDORA-2005-985
2005-10-13
---------------------------------------------------------------------
Product : Fedora Core 3
Name : openssl
Version : 0.9.7a
Release : 42.2
Summary : The OpenSSL toolkit.
Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.
---------------------------------------------------------------------
* Tue Oct 11 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7a-42.2
- fix CAN-2005-2969 - remove SSL_OP_MSIE_SSLV2_RSA_PADDING which
disables the countermeasure against man in the middle attack in SSLv2
(#169863)
- more fixes for constant time/memory access for DSA signature algorithm
- updated ICA engine patch
- install ca-bundle.crt as a config file
---------------------------------------------------------------------
This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
385070cd4cbcef6beb59571066a08baf SRPMS/openssl-0.9.7a-42.2.src.rpm
dd28b6aba5377c64da20c05e2c60722e x86_64/openssl-0.9.7a-42.2.x86_64.rpm
062d09908f7777387958b35c71112215 x86_64/openssl-devel-0.9.7a-42.2.x86_64.rpm
cf47c8a41605ee78213f0ed54b81d01c x86_64/openssl-perl-0.9.7a-42.2.x86_64.rpm
7dd0586966ce231751013a66050c1cd1 x86_64/debug/openssl-debuginfo-0.9.7a-42.2.x86_64.rpm
5771664b0590b304c5d2a06dba276642 x86_64/openssl-0.9.7a-42.2.i386.rpm
797ddd44ea165b234463a80107f14f18 x86_64/openssl-0.9.7a-42.2.i686.rpm
5771664b0590b304c5d2a06dba276642 i386/openssl-0.9.7a-42.2.i386.rpm
26a292002e9806eb6331ade376c04c68 i386/openssl-devel-0.9.7a-42.2.i386.rpm
1c2676b06b305fcc3e82b79a641cdbb7 i386/openssl-perl-0.9.7a-42.2.i386.rpm
a8599ed6c62d679dc4f5aa4bd0b63131 i386/debug/openssl-debuginfo-0.9.7a-42.2.i386.rpm
797ddd44ea165b234463a80107f14f18 i386/openssl-0.9.7a-42.2.i686.rpm
ac7dd0ec8c3e1d57b580ceffce7f37bb i386/debug/openssl-debuginfo-0.9.7a-42.2.i686.rpm
This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.