LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 03-20-2015, 10:58 AM   #1
1337_powerslacker
Member
 
Registered: Nov 2009
Location: Kansas, USA
Distribution: Slackware64-15.0
Posts: 862
Blog Entries: 9

Rep: Reputation: 592Reputation: 592Reputation: 592Reputation: 592Reputation: 592Reputation: 592
OpenSSL upgrade for possible security vulnerabilities


I was alerted this morning to possible vulnerabilities in this article. According to the article, -current has the latest patches which are recommended, but for the sake of peace of mind, I went to the OpenSSL site, downloaded the latest sources, and built the package(s). As a public service for all Slackers utilizing this forum, I have uploaded the packages, and am offering it for download to anyone interested.

openssl-1.0.2a
openssl-solibs-1.0.2a

Please note that these are for x86-64 users only, as I only have 64-bit hardware.

Happy Slacking!

Regards,

Matt
 
Old 03-20-2015, 12:55 PM   #2
Didier Spaier
LQ Addict
 
Registered: Nov 2008
Location: Paris, France
Distribution: Slint64-15.0
Posts: 11,057

Rep: Reputation: Disabled
Thanks but I wouldn't recommend to replace the patched openssl{,-solibs} official Slackware package, released on Fri, 9 Jan 2015 with a third-party one. Furthermore you don't say for which Slackware version it is build (is it for -current?), nor provide build material at time of writing.

I'd suggest instead to just follow the official Security Advisory or for a very sensitive installation rebuild the packages with one of the patched versions linked to by mancha in this post.

Last edited by Didier Spaier; 03-22-2015 at 10:46 AM.
 
1 members found this post helpful.
Old 03-20-2015, 01:05 PM   #3
veerain
Senior Member
 
Registered: Mar 2005
Location: Earth bound to Helios
Distribution: Custom
Posts: 2,524

Rep: Reputation: 319Reputation: 319Reputation: 319Reputation: 319
Who would trust your copies of software. As good policy only signed (DSA) packages should be used/installed from official source.
 
Old 03-20-2015, 01:36 PM   #4
1337_powerslacker
Member
 
Registered: Nov 2009
Location: Kansas, USA
Distribution: Slackware64-15.0
Posts: 862

Original Poster
Blog Entries: 9

Rep: Reputation: 592Reputation: 592Reputation: 592Reputation: 592Reputation: 592Reputation: 592
Didier: I used PV's SlackBuild from a mirror site, and I am using -current. I should have made that clear. As for 'build material', it is unclear exactly what you mean, unless you are referring to the SlackBuild (I didn't compile it manually).

veerain: Trust has to start somewhere, and although I am not mancha and have not, as yet, have a proven reputation for reliability, I do have a vested interest in seeing my system run smoothly, as I am a fellow Slacker. The packages are available; do with it (or not) as you will. If you want to wait for an official source to come out with the patched version, that is your prerogative. I am merely making updated packages available for download because I thought fellow Slackers would be interested in knowing about the vulnerability, and upgrading. Perhaps I assumed too much in building the package myself, given the emphasis on security; using a trusted site is far preferred to a random site (such as how mine would be perceived at the present).

Happy Slacking!
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Docker Updates for Three Security Vulnerabilities LXer Syndicated Linux News 0 12-15-2014 06:00 PM
LXer: New OpenSSL Vulnerabilities Rediscovered and Fixed Four Years After Initial Report LXer Syndicated Linux News 0 05-06-2014 01:30 PM
[Slackware Security]: Some pending vulnerabilities... mancha Slackware 7 08-22-2013 09:08 AM
Has Centos 4.3 Security Vulnerabilities? Seregwethrin Linux - Server 3 02-29-2008 09:48 AM
OpenSSL Advisory: ASN.1 parsing vulnerabilities unSpawn Linux - Security 0 09-30-2003 07:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 12:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration