Debian Linux Security Advisory 1934-1 – A design flaw has been found in the TLS and SSL protocol that allows an attacker to inject arbitrary content at the beginning of a TLS/SSL connection. The attack is related to the way how TLS and SSL handle session renegotiations. CVE-2009-3555 has been assigned to this vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82647/dsa-1934-1.txt
Source: https://packetstormsecurity.com/files/82647/Debian-Linux-Security-Advisory-1934-1.html

