oss-sec mailing list archives

Re: OpenSSL 1.0.1 TLS/DTLS hearbeat information disclosure CVE-2014-0160


From: Reed Loden <reed () reedloden com>
Date: Mon, 7 Apr 2014 13:56:27 -0700

I just asked around on IRC, and one of the Ubuntu guys said they didn't
get any prior notification of this, so fixed packages won't be out
until tomorrow at the earliest (for Ubuntu).

Was this not coordinated with the distros at all? If not, that seems
like major fail on the reporters and NCSC-FI's part. :/

2c,
~reed

On Mon, 7 Apr 2014 21:43:46 +0200
Tomas Hoger <thoger () redhat com> wrote:

Hi!

There's a new OpenSSL release 1.0.1g that fixes information leak issue:

http://www.openssl.org/news/secadv_20140407.txt
http://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=96db902
http://heartbleed.com/

-- 
Tomas Hoger / Red Hat Security Response Team


Current thread: