Re: [Security-Discuss] OpenSSl Update?

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 6-Nov-04, at 2:15 PM, Amichai Rotman wrote:

> Hey,
>
> While scanning for rootkits, I got a warning regarding the version of 
> OpenSSL
> (openssl-0.9.7c-3mdk) instaled.
>
> Looking at the OpenSSL site (http://www.openssl.org) reveals a Security
> Advisory regarding this version.
>
> Any plans on releasing the new version (0.9.7e) as an update?

No, 0.9.7e won't be released as an update.  We patch things as much as 
possible... if we updated to that version, we'd have to rebuild and put 
into updates everything that builds against openssl.  What was the 
specific vuln it was mentioning?  The last that I know of was taken 
care of by:

http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:023

0.9.7e fixes bugs, but I didn't see an advisory saying it fixed any 
security issues.

> I am using Proxad as my Update Source for URPMI.

You also don't indicate which mdk version you're using.

-- 
*Please note gpg keyid FE6F2AFD has been replaced with keyid FEE30AD4*
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.