Re: openssl updates

"Konstantin A. Lepikhov" <[email protected]>
Newsgroups gmane.linux.trustix.general
Message-ID <[email protected]>
Hi Denis!

Saturday 02, at 05:47:55 AM you wrote:

> 
> I use TSL 2.2 (the latest stable version) with all last updates except
> the kernel (by swup).
> 
> Some days ago I tried to compile the latest version of BIND on such
> machine, and its configure script gave me the following warning:
> 
> "Your OpenSSL crypto library may be vulnerable to
> one or more of the the following known security  
> flaws:                                           
>                                                  
> CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and  
> CVE-2006-2940.                                   
>                                                  
> It is recommended that you upgrade to OpenSSL    
> version 0.9.8d/0.9.7l (or greater)."
> 
> # grep openssl /var/log/rpmpkgs
> openssl-0.9.7e-8tr.i586.rpm
> openssl-devel-0.9.7e-8tr.i586.rpm
> openssl-python-0.9.7e-8tr.i586.rpm
> openssl-support-0.9.7e-8tr.i586.rpm
> 
> Is this warning worth considering? Are there plans of updating openssl?
blame the stupid checks in bind configure script - there's no need to bump
version numbers for packages, just apply fix patches for old one.

-- 
WBR et al.

_______________________________________________
tsl-discuss mailing list
[email protected]
http://lists.trustix.org/mailman/listinfo/tsl-discuss
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFFcU6T3TEpd8GO1nMRAoldAJ43XUAeNiL+JbBcdm2feSUu/rdDwgCePoqE
gOx2U49MlwWV33moERwjANY=
=0E0i
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.