看板FB_security
標 題Re: ports requiring OpenSSL not honouring OpenSSL from ports
發信站NCTU CS FreeBSD Server (Thu May 1 05:48:20 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
[CC'd to freebsd-ports]
On 28.04.2014, at 00:50, Jamie Landeg-Jones <
[email protected]> wrote:
> Scot Hetzel <[email protected]> wrote:
> Here's a list of some that link against /lib/libcrypto.so.7 and/or
> /lib/libssl.so.7
[...]
> devel/android-tools-adb
> net-p2p/transmission-cli
> net-p2p/transmission-daemon
> net/socat
> net/svnup
> ports-mgmt/pkg
> security/john
> security/scrypt
> security/trousers
> sysutils/tarsnap
+ www/nginx
It took me some time to realize that nginx continued to be vulnerable (heartbleed) even after:
1) creating upgraded poudriere jail (svn,stable10)
2) rebuilding all installed ports in that jail by poudriere
3) reinstalling all ports
4) rebuilding world and kernel (svn, stable10)
5) rebooting
Well, I should have started with 4) instead. Now I know ;-)
Regards,
Michael
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"