DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 9th January 2015
shep shep is offline
Real Name: Scott
Arp Constable
 
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,507
Default OpenSSL 1.0.1k released with 8 security fixes

http://www.openssl.org/news/secadv_20150108.txt

Of interest, none of the reports reference the Libressl project.
Reply With Quote
  #2   (View Single Post)  
Old 9th January 2015
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,984
Default

Per Bob Beck, these CVEs were addressed by LibreSSL in May.

https://twitter.com/bob_beck/status/553233391164743682
Reply With Quote
  #3   (View Single Post)  
Old 12th January 2015
sysfu sysfu is offline
Port Guard
 
Join Date: Jun 2008
Posts: 36
Default

Thx for posting Beck's tweet Jiggimi, I had been wondering if any of the recent OpenSSL vulns were present in LibreSSL.
Reply With Quote
  #4   (View Single Post)  
Old 16th January 2015
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,984
Default

Further review found some minor applicable components. Ted Unangst posted this on the OpenBSD tech@ mailing list:
Code:
After some review of the issues fixed in the latest OpenSSL release,
we will not be publishing errata for them. Referring to:

https://www.openssl.org/news/secadv_20150108.txt

Several of the reported issues are in code removed from 5.6, and the
remainder appear to be low impact. They will of course be fixed in cvs
going forward, but at this time, the impact is low enough that it
doesn't outweight the stress of patching.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security More 'Ruby on Rails' security fixes released J65nko News 0 12th February 2013 11:01 PM
OpenSSL fixes DoS bug in recent bug fix J65nko News 0 20th January 2012 12:02 AM
Security Six security flaws fixed in OpenSSL J65nko News 0 6th January 2012 06:17 PM
New version of OpenSSL fixes two vulnerabilities J65nko News 0 9th December 2010 02:56 AM
OpenSSL Security Advisory [24 March 2010] J65nko News 0 29th March 2010 11:12 PM


All times are GMT. The time now is 12:34 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick