Re[4]: About the openssl hole

From: Gabriel Ambuehl (gaml@buz.ch)
Date: 07/30/02


Date: Tue, 30 Jul 2002 19:04:34 +0200
From: Gabriel Ambuehl <gaml@buz.ch>
To: Geir Råness <pulz@pulz.no>


-----BEGIN PGP SIGNED MESSAGE-----

Hello Geir,

Tuesday, July 30, 2002, 6:56:12 PM, you wrote:

> I talked with an freind of mine who tried this solution, and he told
me that it where only one patch that failed.
> If you remove the patch "patch-ah" the build will go fine.

> But as many know, the port of openssl will not completly replace the
core openssl.
> (You could see this if you build mod_ssl)

Well I could live without mod_ssl for the next hours, but I can't just
go shutdown ssh on all boxes cause that would mean I'd have to go
onsite to some 4 NOCs (two of them on the other side of the world) to
have SSH get backup. Hmm. Maybe I'll just shut all SSL stuff down and
have the NOC monkeys reboot them when the patch is here....

What's happening (I suppose) is that the port gets installed to
/usr/local/lib whereas the the old version still is in /usr/lib where
it belongs to as part of the base system which means that you probably
have to overwrite the old lib by hand but I wouldn't want to guarantee
that nothing is going to break if you do this. To make it short: it's
probably best to just wait and update your boxes ASAP (I'm just glad I
just got a bunch of Athlon XP 1800+ boxes which do make world in no
time
;-).

Best regards,
 Gabriel

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.0.2i

iQEVAwUBPUa5GcZa2WpymlDxAQFzZwf/RhCHnyKm0feKzFZXJ0/DTD6f5jfQE1cM
pUqr7VEcdQ8cRjG8mMJDZ0eYV50DiJZVQmzTLfQwpvurE34YNSP5oxqsAAEwT8sb
MRf1l32mEnvLK5AgfWTT5vXlT4hwTftmQJ48vYZMAk2Xt4Grr+7TD4IzfY5S9F1J
WBwjTlgBsu+4xE5mG2Ra1AUebdMsIT12tEuIsyQnBjXCEi6miuwbivNrjt4ay//i
aiavUsfVGpUSgOi5DxZwiuSsMTr3Zv6ne/6Clcpupmk4MolqUb5l90oLhZXfqlE0
4FZ0eyv5YwdiPEjQ+SOdpqa81rYe8SU2MC9PQ1QHQseeL3VNv1KVcA==
=6GuU
-----END PGP SIGNATURE-----

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: AW: Slow Network with rl0 and 5.3
    ... > your patch works like a charme. ... > installing it on 2 production boxes where customers really have problems. ... It is, however, a valid workaround until the ... real problem is identified. ...
    (freebsd-stable)
  • Re: VS.NET and 64 Bit AMD Athlon
    ... It appears that McAfee has a patch out to fix this problem. ... Patch 5 for McAfee VirusScan Enterprise 8.0i ... List boxes and Message boxes in .NET applications do not display any ... Toolbar icons in some applications display as black boxes. ...
    (microsoft.public.vsnet.general)
  • Re: Desktop file named ~ keeps re-creating itself
    ... | address book file ... |>a glitch introduced in the patch). ... |>> bunch of boxes. ... I used Word to open it and got a bunch ...
    (microsoft.public.security)
  • XP firewall disabled
    ... Fresh install of SBS 2003 standard fully patched including the patch for ... SP2 on XP. ... I have added 8 XP boxes to the domain without a hitch. ...
    (microsoft.public.windows.server.sbs)