D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 


On 08/04/14 10:42, Philip Hudson wrote:
On 8 April 2014 09:10, Martijn Grooten <martijn@xxxxxxxxxxxxxxxxxx> wrote:
Things rarely get more serious than this:

http://arstechnica.com/security/2014/04/critical-crypto-bug-in-openssl-opens-two-thirds-of-the-web-to-eavesdropping/
http://heartbleed.com/

Just checked OpenSSH dependencies in debian apt, and they do include
libssl, so I guess OpenSSH is one of the affected apps. Damn.

So is this easy to fix then or is it more complex than just patching the issue and releasing an updated version.

Paul

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq