D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSL 1.0.1 "Heartbleed" vulnerability

 

On Tue, Apr 08, 2014 at 09:27:38AM +0000, Rob Beard wrote:
> I've spent the morning updating our Debian servers at work, but there's
> something I wasn't entirely clear about.  According to the Ars article the
> Private Keys can be recovered, am I right in thinking this would affect SSL
> keys, TLS keys on e-mail servers and keys used on OpenVPN?

That's what I understand, yes. Anything that uses OpenSSL version 1.0.1
(up to 1.0.1f)) is vulnerable.

Martijn.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq