看板FB_security
標 題Re: http://heartbleed.com/
發信站Sentex Communications (Tue Apr 8 06:27:09 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On 4/7/2014 5:02 PM, Xin Li wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
> Hi, Thomas,
>
> On 04/07/14 13:49, Thomas Steen Rasmussen wrote:
>> Hello,
>>
>>
http://heartbleed.com/ describes an openssl vulnerability
>> published today. We are going to need an advisory for the openssl
>> in base in FreeBSD 10 and we are also going to need an updated
>> port.
>>
>> The implications of this vulnerability are pretty massive,
>> certificates will need to be replaced and so on. I don't want to
>> repeat the page, so go read that.
>
> We are already working on this but building, reviewing, etc. would
> take some time.
>
Hi,
The webpage lists
FreeBSD 8.4 (OpenSSL 1.0.1e) and 9.1 (OpenSSL 1.0.1c)
I take it this is only if you installed from the ports no ?
---Mike
--
-------------------
Mike Tancsa, tel +1 519 651 3400
Sentex Communications,
[email protected]
Providing Internet services since 1994 www.sentex.net
Cambridge, Ontario Canada
http://www.tancsa.com/
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"