看板FB_security
標 題RE: CVE-2014-0160?
發信站NCTU CS FreeBSD Server (Fri Apr 11 23:10:39 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On Fri, 11 Apr 2014,
[email protected] wrote:
> ext 65281 (renegotiation info, length=3D1)
> ext 00011 (EC point formats, length=3D4)
> ext 00035 (session ticket, length=3D0)
> ext 00015 (heartbeat, length=3D1) <-- Your server supports heartbeat. Bug=
is possible when linking against OpenSSL 1.0.1f or older. Let me check.
> Actively checking if CVE-2014-0160 works: Your server appears to be patch=
ed against this bug.
>
> K=F6sz! ;-)
>
> Is there any reason why nightly security patches are not enabled by defau=
lt in FreeBSD?
Very easy to configure download and notification if you use =
freebsd-update:
Add to /etc/crontab:
@daily root /usr/sbin/freebsd-update cr=
on
In your daily e-mail log you can see, if any changes happened in the =
freebsd-update reposity. Then you can decide when to up-date.
Regards,
Janos Mohacsi
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"