Re: [Security-Discuss] OpenSSl Update?
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 8-Nov-04, at 4:14 AM, Amichai Rotman wrote:
>>> While scanning for rootkits, I got a warning regarding the version of
>>> OpenSSL
>>> (openssl-0.9.7c-3mdk) instaled.
>>>
>>> Looking at the OpenSSL site (http://www.openssl.org) reveals a
>>> Security
>>> Advisory regarding this version.
>>>
>>> Any plans on releasing the new version (0.9.7e) as an update?
>>
>> No, 0.9.7e won't be released as an update. We patch things as much as
>> possible... if we updated to that version, we'd have to rebuild and
>> put
>> into updates everything that builds against openssl. What was the
>> specific vuln it was mentioning? The last that I know of was taken
>> care of by:
>
> My bad,
>
> I am using MDK 10.0 Official, and the link below relates to MDK 9.2.
> Should I
> d/l the 9.2 package then? This is the package I have installed:
>
> openssl-0.9.7c-3mdk
>
> and the rootkit hunter has this listed as a vul version.
Ummm... no... don't install the 9.2 version. That would be... silly.
However, if you do a "rpm -qi openssl --changelog|less" you'll see a
changelog entry, from me, that indicates patches have been applied to
fix the issues cited in that advisory.
rkhunter, unfortunately, detects by version, and since we have an older
version (although it has the appropriate patches applied), it will
always report it as vulnerable.
I really disagree with programs arbitrarily deciding that a version of
xyz software is vulnerable solely based on the version number.
You can ignore that.
--
*Please note gpg keyid FE6F2AFD has been replaced with keyid FEE30AD4*
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed