Details
-
Task
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Fixed
-
None
-
5.5.45
Description
Debian reported a bug in an older version of MariaDB relating to using a 512-bit modulus when
negotiating a Finite-Field Diffie-Hellman Ephemeral (FFDHE) handshake in TLS.
This was increased to 1024 in 10.0.18, but MySQL increased this to 2048 in their 5.7.7 release in Oct 2014, and the current consensus is that, while 1024 is currently sufficient, it's unlikely to be in the near to medium future.
Debian bug report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=788905
Attachments
Issue Links
- links to