A good reason to upgrade to 15.0

Post your comments, questions, bug reports or suggest new features for alphaOS
Scooby
Site Admin
Posts: 826
Joined: 09 Sep 2013, 16:52

A good reason to upgrade to 15.0

Postby Scooby » 21 Apr 2014, 11:12

A vulnerability in openssl has been found called heartbleed

Image

"The Electronic Frontier Foundation,[10] Ars Technica,[11] and Bruce Schneier[12] all deemed the Heartbleed bug "catastrophic".
Forbes cybersecurity columnist Joseph Steinberg wrote, "Some might argue that [Heartbleed] is the worst vulnerability found
(at least in terms of its potential impact) since commercial traffic began to flow on the Internet."[13]"

Although most severe for attacking servers it could be used by a malicious server
to read data from the client's memory such as website usernames and passwords.

Security firms advice to change passwords.
on your internet sites

read more:
http://en.wikipedia.org/wiki/Heartbleed

I checked on alphaOS 14.5 - and it has the exploit
( that same goes at least for my 32-bit alphaos and probably
for older versions as well.)

Code: Select all

[root@alphaos] > openssl version
OpenSSL 1.0.1e 2 Nov 2013


on 15.0 - SAFE

Code: Select all

[root@alphaos] > openssl version
OpenSSL 1.0.1g 7 Apr 2014

Scooby
Site Admin
Posts: 826
Joined: 09 Sep 2013, 16:52

Re: A good reason to upgrade to 15.0

Postby Scooby » 21 Apr 2014, 12:00

Can try these modules with latest versions of openssl for alphaOS 14.5 and older.
(put in modules/ dir)

I tried it on 64-bit 14.5 and it seems to work OK

64-bit
openssl-1.0.1.g-1.sb

32-bit
openssl-1.0.1.g-1-32-bit.sb

tigs
Advanced
Posts: 50
Joined: 05 Feb 2014, 00:57

Re: A good reason to upgrade to 15.0

Postby tigs » 21 Apr 2014, 23:46

Hi Scooby,

Any plan to make the 32-bit version of 15?

Scooby
Site Admin
Posts: 826
Joined: 09 Sep 2013, 16:52

Re: A good reason to upgrade to 15.0

Postby Scooby » 22 Apr 2014, 18:19

Sure, why not :D

tigs
Advanced
Posts: 50
Joined: 05 Feb 2014, 00:57

Re: A good reason to upgrade to 15.0

Postby tigs » 23 Apr 2014, 02:15

Scooby wrote:Sure, why not :D

look forward to trying it out. thanks for your great work and support


Return to “General Discussion”

Who is online

Users browsing this forum: No registered users and 14 guests

cron