Feedback
Did this article resolve your question/issue?

   

Article

Are Connect for ODBC products affected by OpenSSL Security Advisory dated 1st March 2016 , specifically CVE-2016-0800 (DROWN) vulnerability ?

Information

 
TitleAre Connect for ODBC products affected by OpenSSL Security Advisory dated 1st March 2016 , specifically CVE-2016-0800 (DROWN) vulnerability ?
URL NameAre-the-Connect-for-ODBC-products-affected-by-OpenSSL-Security-Advisory-dated-1st-March-2016-specifically-CVE-2016-0800-DROWN-vulnerability
Article Number000183481
EnvironmentProduct: Connect for ODBC drivers
Version: 7.1.5
OS: All supported platforms
Database: All supported databases
Application: All supported applications
Question/Problem Description

Are the Connect for ODBC products affected by OpenSSL Security Advisory dated 1st March 2016 , specifically CVE-2016-0800 (DROWN) vulnerability ?
https://www.openssl.org/news/secadv/20160301.txt

Steps to Reproduce
Clarifying Information
Error Message
Defect Number
Enhancement Number
Cause
Resolution

Cross-protocol attack on TLS using SSLv2 (DROWN) (CVE-2016-0800) is a server-side vulnerability and does not affect clients.
Progress DataDirect has reviewed our products and determined that all of the on-premise ODBC drivers are NOT affected by DROWN since the on-premise ODBC drivers operate as clients.

Regarding the other security advisories that were announced along with DROWN on March 1, 2016 : These vulnerabilities have little or no impact on the on-premise ODBC driver products.

For more details see : 
https://community.progress.com/community_groups/datadirect_connect/f/16/t/23584

Workaround
Notes
Last Modified Date5/19/2016 11:26 AM
Files
Disclaimer The origins of the information on this site may be internal or external to Progress Software Corporation (“Progress”). Progress Software Corporation makes all reasonable efforts to verify this information. However, the information provided is for your information only. Progress Software Corporation makes no explicit or implied claims to the validity of this information.

Any sample code provided on this site is not supported under any Progress support program or service. The sample code is provided on an "AS IS" basis. Progress makes no warranties, express or implied, and disclaims all implied warranties including, without limitation, the implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample code is borne by the user. In no event shall Progress, its employees, or anyone else involved in the creation, production, or delivery of the code be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample code, even if Progress has been advised of the possibility of such damages.