>Also, anything before OpenSSL 0.9.7c or 0.9.6k is not viable because of a recent
>CERT. Please see:
>http://www.cert.org/advisories/CA-2003-26.html
Yes but generally, distros backport patches to older release so that they don't break the global way the soft run...
For RH, openssl-0.9.7a-20 is considered corrected although it is versioned 0.9.7a and not 0.9.7c
Please see
https://rhn.redhat.com/errata/RHSA-2003-292.html
Hope we won't have to publish our openssl packages for pgA3!
Regards,
Raphaël