From owner-freebsd-questions@FreeBSD.ORG Wed Apr 9 18:52:05 2014 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 4347C2CA for ; Wed, 9 Apr 2014 18:52:05 +0000 (UTC) Received: from neonpark.inter-sonic.com (neonpark.inter-sonic.com [212.247.8.98]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client CN "neonpark.inter-sonic.com", Issuer "StartCom Class 2 Primary Intermediate Server CA" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 05C3B10FC for ; Wed, 9 Apr 2014 18:52:04 +0000 (UTC) X-Virus-Scanned: amavisd-new at BSDLabs AB Message-ID: <5345955D.5080209@intersonic.se> Date: Wed, 09 Apr 2014 20:45:49 +0200 From: Per olof Ljungmark Organization: Intersonic AB User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:24.0) Gecko/20100101 Thunderbird/24.3.0 MIME-Version: 1.0 To: "freebsd-questions@freebsd.org" Subject: Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-14:06.openssl [REVISED] References: <201404090106.s3916VRm035425@freefall.freebsd.org> In-Reply-To: <201404090106.s3916VRm035425@freefall.freebsd.org> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 09 Apr 2014 18:52:05 -0000 Can someone please shed a little light why this advisory says STABLE/9 is affected, but https://heartbleed.com/ says it is not? I see openssl version -a OpenSSL 0.9.8y 5 Feb 2013 built on: date not available platform: FreeBSD-amd64 options: bn(64,64) md2(int) rc4(ptr,int) des(idx,cisc,16,int) blowfish(idx) compiler: cc OPENSSLDIR: "/etc/ssl" from our STABLE/9 servers. What am I missing here? On 2014-04-09 03:06, FreeBSD Security Advisories wrote: > ============================================================================= > FreeBSD-SA-14:06.openssl Security Advisory > The FreeBSD Project > > Topic: OpenSSL multiple vulnerabilities > > Category: contrib > Module: openssl > Announced: 2014-04-08 > Affects: All supported versions of FreeBSD. > Corrected: 2014-04-08 18:27:39 UTC (stable/10, 10.0-STABLE) > 2014-04-08 18:27:46 UTC (releng/10.0, 10.0-RELEASE-p1) > 2014-04-08 23:16:19 UTC (stable/9, 9.2-STABLE) > 2014-04-08 23:16:05 UTC (releng/9.2, 9.2-RELEASE-p4) > 2014-04-08 23:16:05 UTC (releng/9.1, 9.1-RELEASE-p11) > 2014-04-08 23:16:19 UTC (stable/8, 8.4-STABLE) > 2014-04-08 23:16:05 UTC (releng/8.4, 8.4-RELEASE-p8) > 2014-04-08 23:16:05 UTC (releng/8.3, 8.3-RELEASE-p15) > CVE Name: CVE-2014-0076, CVE-2014-0160 >