Re: FreeBSD Security Advisory FreeBSD-SA-03:18.openssl

From: Bjoern A. Zeeb (bzeeb-lists_at_lists.zabbadoz.net)
Date: 10/04/03

  • Next message: Colin Percival: "Re: FreeBSD Security Advisory FreeBSD-SA-03:18.openssl"
    Date: Sat, 4 Oct 2003 00:06:05 +0000 (UTC)
    To: freebsd-security@freebsd.org
    
    

    On Fri, 3 Oct 2003, FreeBSD Security Advisories wrote:

    Hi,

    > V. Solution
    >
    > Perform one of the following:
    ...
    > 2) To patch your present system:
    ...
    > c) Recompile the operating system as described in
    > <URL: http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html >.
    >
    > Note that any statically linked applications that are not part of the
    > base system (i.e. from the Ports Collection or other 3rd-party sources)
    > must be recompiled.

    this seems to be a default disclaimer for the openssl advisories but
    at this point I am asking myself if there are any applications
    statically linked against librypto or libssl in the base system ?

    from what I can see no API is changed with this patch so wouldn't it be
    possible to recompile libssl/libcrypto and install only them instead of
    rebuilding the complete base system as suggested (assuming nothing in
    the base system is statically linked against one of the two) ?

    -- 
    Greetings
    Bjoern A. Zeeb				bzeeb at Zabbadoz dot NeT
    56 69 73 69 74				http://www.zabbadoz.net/
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Colin Percival: "Re: FreeBSD Security Advisory FreeBSD-SA-03:18.openssl"

    Relevant Pages

    • Re: Request for test/comments: OpenSSL 0.9.8b import
      ... I have been working on preparing an import of OpenSSL 0.9.8b into the ... currently have in the base system) so I choose to bump the library ... In OpenSSL 0.9.8b the API libmp uses is broken so libmp has been ... The patch can be applied while standing in your src/ directory using: ...
      (freebsd-current)
    • Re: FreeBSD Security Advisory FreeBSD-SA-03:08.realpath
      ... >a) Download the relevant patch... ... >c) Recompile your operating system... ... Once the binary updates are available, FreeBSD Update ...
      (FreeBSD-Security)
    • Re: Purpose of defmethod
      ... Frode Vatvedt Fjeld wrote: ... and patch them if the function gets redefined. ... you need to recompile the call ... have to recalculate the program counter. ...
      (comp.lang.lisp)
    • Re: Request for test/comments: OpenSSL 0.9.8b import
      ... I have been working on preparing an import of OpenSSL 0.9.8b into the ... currently have in the base system) so I choose to bump the library ... In OpenSSL 0.9.8b the API libmp uses is broken so libmp has been ... The patch can be applied while standing in your src/ directory using: ...
      (freebsd-current)
    • Re: flash plugin and firefox
      ... saying the sources of the base system is very generic. ... Then what is supposed I have to patch? ... You don't have the sources of the base system. ... The FreeBSD Handbook is your friend: http://www.freebsd.org/doc/handbook/ ...
      (freebsd-questions)