openssl updates

Denis Solovyov <[email protected]>
Newsgroups gmane.linux.trustix.general
Organization Aldema EC / Siberian Web / WOOD.RU
Message-ID <[email protected]>
I use TSL 2.2 (the latest stable version) with all last updates except
the kernel (by swup).

Some days ago I tried to compile the latest version of BIND on such
machine, and its configure script gave me the following warning:

"Your OpenSSL crypto library may be vulnerable to
one or more of the the following known security  
flaws:                                           
                                                 
CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and  
CVE-2006-2940.                                   
                                                 
It is recommended that you upgrade to OpenSSL    
version 0.9.8d/0.9.7l (or greater)."

# grep openssl /var/log/rpmpkgs
openssl-0.9.7e-8tr.i586.rpm
openssl-devel-0.9.7e-8tr.i586.rpm
openssl-python-0.9.7e-8tr.i586.rpm
openssl-support-0.9.7e-8tr.i586.rpm

Is this warning worth considering? Are there plans of updating openssl?

Best regards,
Denis Solovyov
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.