Re: OpenSSL workaround

From: Jacques A. Vidrine (nectar@freebsd.org)
Date: 07/31/02


Date: Tue, 30 Jul 2002 22:21:31 -0500
From: "Jacques A. Vidrine" <nectar@freebsd.org>
To: "H. Wade Minter" <minter@lunenburg.org>

On Tue, Jul 30, 2002 at 10:13:05PM -0400, H. Wade Minter wrote:
> I saw that openssl got committed to RELENG_4_6 today, but haven't seen a
> security announcement go by. What's the recommended way to patch this
> openssl hole?

You can cvsup to RELENG_4_6.

I probably won't send out the announcement until I've finished with
RELENG_4_5 and RELENG_4_4, and that won't be tonight. For various
reasons, merging and testing the upgrade is time consuming.

Cheers,

-- 
Jacques A. Vidrine <n@nectar.cc>                 http://www.nectar.cc/
NTT/Verio SME          .     FreeBSD UNIX     .       Heimdal Kerberos
jvidrine@verio.net     .  nectar@FreeBSD.org  .          nectar@kth.se
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: HEADS UP: OpenSSL problems after GCC 4.2 upgrade
    ... with GCC 4.2. ... our OpenSSL maintainerare currently en-route ... best way to fix the code and to integrate the fix into OpenSSL, ... People are advised to patch their ...
    (freebsd-current)
  • Re: HEADS UP: OpenSSL problems after GCC 4.2 upgrade
    ... aggressively de-supported by GCC 4.2 and GCC goes as far as inserting ... Just in case mailing list will eat the attachment, the patch can be ... our OpenSSL maintainerare currently en-route from ... I haven't seen enough reports of this patch working to be really ...
    (freebsd-current)
  • Re: Welche Distris kommen in Frage
    ... Das System mit den Sicherheitsupdates für die Anwender funktionierte ... Valgrind-Warnungen angesprochen, und nachgefragt, ob der Patch ok sei. ... Das sagt mindestens ebenso viel über die Dämlichkeit des OpenSSL Projekts ... Freiheit ist immer die Freiheit der Andersdenkenden. ...
    (de.comp.os.unix.linux.misc)
  • Re: Problems compiling some ports after upgrading to gcc 4.2.0
    ... the program will abort dsaparam.c:436: warning: function called ... Apply this patch and rebuild openssl. ... Fix runtime crash in OpenSSL with "Illegal instruction" by making some ...
    (freebsd-current)
  • Re: Request for test/comments: OpenSSL 0.9.8b import
    ... I have been working on preparing an import of OpenSSL 0.9.8b into the ... currently have in the base system) so I choose to bump the library ... In OpenSSL 0.9.8b the API libmp uses is broken so libmp has been ... The patch can be applied while standing in your src/ directory using: ...
    (freebsd-current)