Re: openssl updates
Vidar Tyldum Hansen <[email protected]>
| Newsgroups | gmane.linux.trustix.general |
|---|---|
| Message-ID | <[email protected]> |
Denis Solovyov skrev: >>> CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and >>> CVE-2006-2940. >>> # grep openssl /var/log/rpmpkgs >>> openssl-0.9.7e-8tr.i586.rpm >>> Is this warning worth considering? Are there plans of updating openssl? > KAL> blame the stupid checks in bind configure script - there's no need to bump > KAL> version numbers for packages, just apply fix patches for old one. > > Have the mentioned issues been already fixed in openssl-0.9.7e-8tr? These fixes are backported. This is what you can easilly do with Open Source Software. Instead of upgrading the package to a new version with new features that might break existing installations, distros can fix the bugs directly in the stable version they are running. Version numbers doesn't mean a thing in this context.