Skip to main content
Participant
August 7, 2014
Question

Openssl vulnerability -- Adobe Connect 8.2

  • August 7, 2014
  • 1 reply
  • 310 views

What is the supported patch / fix for Adobe Connect 8.2 and Openssl vulnerabilities discovered over the last few months?  I'm assuming it is due to an old stunnel implementation.

The remote service accepted an SSL ChangeCipherSpec message at an incorrect point in the handshake 
leading to weak keys being used, and then attempted to decrypt an SSL record using those weak keys.

CVE-2010-5298


CVE-2014-0076


CVE-2014-0195


CVE-2014-0198


CVE-2014-0221


CVE-2014-0224

CVE-2014-3470

    This topic has been closed for replies.

    1 reply

    Jorma_at_Knox
    Legend
    August 7, 2014

    You should go and download the Stunnel application and replace the version included with Connect 8.2. stunnel: Downloads

    So you are aware, Connect 9 and newer installers no longer come with Stunnel, So you will need to go to Stunnel's site to download the latest version when upgrading (unless you are already on the latest version).