LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 12-07-2015, 12:03 AM   #1
Altiris
Member
 
Registered: Mar 2013
Posts: 556

Rep: Reputation: Disabled
Is openssl version in Slackware vulnerable to these new issues?


I noticed Debian has made patches for OpenSSL for their distro and I found this link https://www.openssl.org/news/secadv/20151203.txt which include 1.0.1e however I believe Slackware 14.1 is using 1.0.1p from the patches repo? So, is Slackware vulnerable to these things or no? I am not really sure how to tell.
 
Old 12-07-2015, 12:33 AM   #2
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656
If you look at each advisory, it will tell you the recommended version to get away from these issues. CVE-2015-3194 and CVE-2015-3195 require 1.0.1q while CVE-2015-3196 requires 1.0.1p (so we aren't affected by the second). The others only affect 1.0.2, which is not on 14.1. Both issues are classified as "moderate" and don't seem to cause any potential hacking points. Pat only provides patches when he feels the severity warrants the possible instability a patch can introduce. So we'll have to wait and see if he decides to put out patches.

If you're worried about these issues, it might be worth updating to the newer version yourself and then if Pat releases a version later, you can just install that (if desired).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] I think my version of SSL isn't vulnerable to Heartbleed, but I want to make sure nerdofdarkness Linux - Newbie 6 04-13-2014 07:38 PM
[SOLVED] OpenSSL version and libssl.so/libcrypto.so version mismatch pbidwell Linux - Software 3 08-11-2012 11:34 AM
Some Linux Distros Vulnerable to Version of DLL Hijacking Bug win32sux Linux - Security 1 08-28-2010 10:49 PM
Slackware Gnome version issues ComputerMan Slackware 6 08-25-2005 10:21 PM
- OpenSSL 0.9.7c [ Vulnerable ] tekmorph Linux - Security 1 11-21-2004 09:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 12:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration