Re: OpenSSL warning from dns/bind95 build...?



Chuck Swiger wrote:
Hi, all--

Apropos of this security issue with BIND, I just tried updating a FreeBSD-6.3-STABLE system with dns/bind95, and it loudly complains about the OpenSSL version which comes with the system:
[snip]
Is the version of OpenSSL now included with RELENG_6 (OpenSSL 0.9.7e-p1) OK, or is it at risk as reported?

You're better off upgrading using the version in ports/security/openssl and adding WITH_OPENSSL_PORT to /etc/make.conf.

hth,

Doug

--

This .signature sanitized for your protection

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • OpenSSL warning from dns/bind95 build...?
    ... Apropos of this security issue with BIND, I just tried updating a FreeBSD-6.3-STABLE system with dns/bind95, and it loudly complains about the OpenSSL version which comes with the system: ... WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING ...
    (FreeBSD-Security)
  • Re: Apache, mod_ssl and openssl?
    ... > So what happens if I install a new openssl package without recompiling ... > apache and mod_ssl with the new openssl source? ... If you are updating to 0.9.6e or later, ... This is a different bug from the one exploited by slapper but it could ...
    (comp.os.linux.security)