Did RedHat's OpenSSL patch miss Apache?

From: gf gf (unknownsoldier93_at_yahoo.com)
Date: 05/10/04

  • Next message: Soner Eker: "Re: Secure Form Script?"
    Date: Sun, 9 May 2004 20:13:21 -0700 (PDT)
    To: focus-linux@securityfocus.com
    
    

    A while ago, RedHat issued
    https://rhn.redhat.com/errata/RHSA-2004-119.html
    concerning security issues with OpenSSL.

    It seems to me that Apache uses its own copy of
    libssl, which is not part of the openssl RPM and hence
    not updated by the RedHat RPM update. (And is still
    vulnerable).

    $ rpm -q -f /usr/lib/apache/libssl.so
    mod_ssl-2.8.12-3

    mod_ssl is not addressed in RHSA-2004-119.

    (Although there is a previoud adivosory
    https://rhn.redhat.com/errata/RHSA-2003-244.html about
    mod_ssl, it does not seem to address these issues.)

    It seems to me that, if I'm correct, this is a
    critical issue - the RedHat patches are simply
    uncomplete and the servers still vulnerable

            
                    
    __________________________________
    Do you Yahoo!?
    Win a $20,000 Career Makeover at Yahoo! HotJobs
    http://hotjobs.sweepstakes.yahoo.com/careermakeover


  • Next message: Soner Eker: "Re: Secure Form Script?"

    Relevant Pages

    • openssl | RH Enterpsie | 0.9.7a??
      ... Redhat, so I'm hoping someone can offer a general suggestion on how to ... Redhat Enterprise WS comes with openSSL 0.9.7.a, as indicated by rpm ... directories - makes doing updates a real pain. ...
      (linux.redhat)
    • Re: Redhat and OpenSSL Manner
      ... I red that redhat never change version of openssl but it's updating. ... enhancements and new features might be backported from newer versions too if they are not introducing any compatibility problems (for example this is often done for kernel package in RHEL to support new hardware). ... If you look into the SRPM packages, you'll see that they contain original unchanged source code wich is the same version as the package version, and also bunch of patches that get applied to that source code prior to compilation. ...
      (RedHat)
    • New OpenSSL remote vulnerability (issue date 2003/10/02)
      ... Mr. Hornik discovered remote vulnerability in OpenSSL package provided ... Affected are all RedHat distributions up to version 8.0 including. ...
      (Bugtraq)
    • Installing new openssl and openssh on RedHat 8.x/9.x
      ... I am about to embark on a round of upgrades for OpenSSL and ... OpenSSH on some systems that are running RedHat 8.0 and 9.0. ... packages are installed from the distro .rpm files. ... libraries are a bit more complicated especially for other dependent products ...
      (comp.security.ssh)
    • .configure failing on redhat 3.0.3
      ... checking whether snprintf correctly terminates long strings... ... checking OpenSSL header version... ... configure: error: OpenSSL version header not found. ... Do you know what is causing this, I had no trouble on the other redhat ...
      (comp.security.ssh)