Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 08 Apr 2014 15:23:35 +0100
From:      Arthur Chance <freebsd@qeng-ho.org>
To:        Matthias Petermann <matthias@petermann-it.de>, freebsd-questions@freebsd.org
Subject:   Re: OpenSSL TLS Heartbeat Security Issue
Message-ID:  <53440667.8060203@qeng-ho.org>
In-Reply-To: <20140408134425.Horde.azH0NUU2X8TUmV9kVtS2MA2@d2ux.org>
References:  <20140408134425.Horde.azH0NUU2X8TUmV9kVtS2MA2@d2ux.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 08/04/2014 12:44, Matthias Petermann wrote:
> Hello,
>
> anyone able to comment on the impact of:
>
>     http://heartbleed.com/
>
> to recent versions of FreeBSD?

There's a thread on freebsd-security@ starting at

http://lists.freebsd.org/pipermail/freebsd-security/2014-April/007404.html

TL;DR: 8.4 & 9.2 not affected *unless* the port version has been 
installed, and the latest port (1.0.1_10) has the fix.

10.0-REL is vulnerable, security advisory pending.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?53440667.8060203>