Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 31 Aug 2014 17:05:23 +0200
From:      Piotr Kubaj <pkubaj@riseup.net>
To:        Brandon Vincent <Brandon.Vincent@asu.edu>,freebsd-security@freebsd.org
Subject:   Re: OpenSSL SA
Message-ID:  <7e908bef-461c-4daf-a1c7-865e37be538c@email.android.com>
In-Reply-To: <CAJm4239s68dRu2Ft1s7j6wsALhr5MRWnptCT1_r7PU%2BxcS_vKw@mail.gmail.com>
References:  <54021C36.6070709@riseup.net> <CAJm4239s68dRu2Ft1s7j6wsALhr5MRWnptCT1_r7PU%2BxcS_vKw@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Yes, I wrote in the original mail that there have been updates to stable/{8,9,10}. What I meant by the lack of SA is that there were no updates to releng/.

On 31 sierpnia 2014 17:02:12 CEST, Brandon Vincent <Brandon.Vincent@asu.edu> wrote:
>On Sat, Aug 30, 2014 at 11:47 AM, Piotr Kubaj <pkubaj@riseup.net>
>wrote:
>> Hello. According to https://www.openssl.org/news/secadv_20140806.txt
>> there's been a known SA in OpenSSL for 24 days. Since then
>> security/openssl has been updated and there have been updates to head
>> and stable{8,9,10} but there hasn't been any FreeBSD SA. Is it that
>so@
>> has somehow forgotten about it, or the vulnerable features are off in
>base?
>
>It looks like OpenSSL 1.0.1i (which fixes all the issues in the SA
>from upstream) was merged into stable on August 7th. The announcement
>from FreeBSD was probably accidentally not published.
>
>Brandon Vincent

- --
Wysłane za pomocą K-9 Mail.
-----BEGIN PGP SIGNATURE-----
Version: APG v1.1.1

iQI8BAEBCgAmBQJUAzmzHxxQaW90ciBLdWJhaiA8cGt1YmFqQGdtYWlsLmNvbT4A
CgkQL2cq6RGx9j6yRhAAlVtQn7Ohi1dPe41uyfjwtL9fpp6xY8uHvWRWLoWY2QYm
yB7V2vJaLsb0Ysa2MxLf8gTlFZy2l5vfQIWDz36DPytNzEcyrnIjJK2NOmxF8SNu
oRs2TnxO3sMgyDz+A50sEquZLINlbJxJWCtccOG/5jYjeP7mON4zw2brNajZmvJF
mOqc8KSFNLUmCPHTdd+YvAB1PTFJfrjotd//k6MPPrqr0WU85g3GzxGHSpALFJII
TT8sBO4a2PNzLMTxf5JVCpaHmA2v6dUTBTBwstHim2Q1MSEa83gNgBDSk8qfwyy/
FjVcLeDsrLF8M/WVHsSLwATmVp0Y5G3ML9337pLnlBZn1vHJfaS2n12zEAarVYLQ
v9+i5ufzu74N+IqnbdUthXv7ZyEM8q7RUdOm+6XN/FzImbnEwPBNIcG00GU+rD1C
KGXd3HnEDO2nneA5ijdrC7Hd/q9SJVx0e+X9ZtyDdUvWLnXqQtBVwp9pLLm1ePlH
2SsxTYwYRIH59aK1YG0B4cyHKfd97vd4ezJLq1hGVEKh9RxcO1Mge34FrZuBYMnS
KWwwiVnScmPTyPM54cXXmrnhWNUW9kO0DmrYb3sZT97aWqpQPDap+EEGES0ePysF
itBjIQyjoNXnwKrDuBhSvn8CHkbTpVMla75UDoU9b+4vexLuxIfB+z418+EdEjs=
=hZsB
-----END PGP SIGNATURE-----




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?7e908bef-461c-4daf-a1c7-865e37be538c>