Re: [Security-Discuss] OpenSSl Update?

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 8-Nov-04, at 4:14 AM, Amichai Rotman wrote:

>>> While scanning for rootkits, I got a warning regarding the version of
>>> OpenSSL
>>> (openssl-0.9.7c-3mdk) instaled.
>>>
>>> Looking at the OpenSSL site (http://www.openssl.org) reveals a 
>>> Security
>>> Advisory regarding this version.
>>>
>>> Any plans on releasing the new version (0.9.7e) as an update?
>>
>> No, 0.9.7e won't be released as an update.  We patch things as much as
>> possible... if we updated to that version, we'd have to rebuild and 
>> put
>> into updates everything that builds against openssl.  What was the
>> specific vuln it was mentioning?  The last that I know of was taken
>> care of by:
>
> My bad,
>
> I am using MDK 10.0 Official, and the link below relates to MDK 9.2. 
> Should I
> d/l the 9.2 package then? This is the package I have installed:
>
> openssl-0.9.7c-3mdk
>
> and the rootkit hunter has this listed as a vul version.

Ummm... no... don't install the 9.2 version.  That would be... silly.

However, if you do a "rpm -qi openssl --changelog|less" you'll see a 
changelog entry, from me, that indicates patches have been applied to 
fix the issues cited in that advisory.

rkhunter, unfortunately, detects by version, and since we have an older 
version (although it has the appropriate patches applied), it will 
always report it as vulnerable.

I really disagree with programs arbitrarily deciding that a version of 
xyz software is vulnerable solely based on the version number.

You can ignore that.

-- 
*Please note gpg keyid FE6F2AFD has been replaced with keyid FEE30AD4*
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.