Re: [Security-Discuss] OpenSSl Update?
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 6-Nov-04, at 2:15 PM, Amichai Rotman wrote:
> Hey,
>
> While scanning for rootkits, I got a warning regarding the version of
> OpenSSL
> (openssl-0.9.7c-3mdk) instaled.
>
> Looking at the OpenSSL site (http://www.openssl.org) reveals a Security
> Advisory regarding this version.
>
> Any plans on releasing the new version (0.9.7e) as an update?
No, 0.9.7e won't be released as an update. We patch things as much as
possible... if we updated to that version, we'd have to rebuild and put
into updates everything that builds against openssl. What was the
specific vuln it was mentioning? The last that I know of was taken
care of by:
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:023
0.9.7e fixes bugs, but I didn't see an advisory saying it fixed any
security issues.
> I am using Proxad as my Update Source for URPMI.
You also don't indicate which mdk version you're using.
--
*Please note gpg keyid FE6F2AFD has been replaced with keyid FEE30AD4*
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed