Re: openssl updates
"Konstantin A. Lepikhov" <[email protected]>
| Newsgroups | gmane.linux.trustix.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Denis! Saturday 02, at 05:47:55 AM you wrote: > > I use TSL 2.2 (the latest stable version) with all last updates except > the kernel (by swup). > > Some days ago I tried to compile the latest version of BIND on such > machine, and its configure script gave me the following warning: > > "Your OpenSSL crypto library may be vulnerable to > one or more of the the following known security > flaws: > > CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and > CVE-2006-2940. > > It is recommended that you upgrade to OpenSSL > version 0.9.8d/0.9.7l (or greater)." > > # grep openssl /var/log/rpmpkgs > openssl-0.9.7e-8tr.i586.rpm > openssl-devel-0.9.7e-8tr.i586.rpm > openssl-python-0.9.7e-8tr.i586.rpm > openssl-support-0.9.7e-8tr.i586.rpm > > Is this warning worth considering? Are there plans of updating openssl? blame the stupid checks in bind configure script - there's no need to bump version numbers for packages, just apply fix patches for old one. -- WBR et al. _______________________________________________ tsl-discuss mailing list [email protected] http://lists.trustix.org/mailman/listinfo/tsl-discuss
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iD8DBQFFcU6T3TEpd8GO1nMRAoldAJ43XUAeNiL+JbBcdm2feSUu/rdDwgCePoqE gOx2U49MlwWV33moERwjANY= =0E0i -----END PGP SIGNATURE-----