OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Patch for OpenSSL and freebsd 4.4

From: Peter Pentchev (roamringlet.net)
Date: Fri Mar 21 2003 - 04:27:08 CST


On Fri, Mar 21, 2003 at 01:57:55AM -0800, Tim Baur wrote:
> On Fri, 21 Mar 2003, Roelf Schreurs wrote:
>
> > I was wondering if there will be a patch release for the 2 new OpenSSl
> > vulnerabilities found this week?
>
> RELENG_4_4 is no longer supported by the security officer. Please review:
>
> http://www.ca.freebsd.org/security/index.html#adv

jedgar committed fixes to a couple of files 13 hours ago, which
seem to address at least one of those vulnerabilities. I believe
there are FreeBSD developers who are actively committed to keeping
the 4.4 security branch alive, so my advice would be to wait a bit
more, the fixes will probably be MFC'd there, too.

G'luck,
Peter

--
Peter Pentchev roamringlet.net roamsbnd.net roamFreeBSD.org
PGP key: http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint FDBA FD79 C26F 3C51 C95E DF9E ED18 B68D 1619 4553
If you think this sentence is confusing, then change one pig.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (FreeBSD)

iD8DBQE+euj77Ri2jRYZRVMRAkdZAJ9goXG4/A0D5IvsqbSMS1wd7vOoPgCfdC7c
ibSZY+qGWie+vu/Iuv07AaQ=
=HEoA
-----END PGP SIGNATURE-----

To Unsubscribe: send mail to majordomoFreeBSD.org
with "unsubscribe freebsd-security" in the body of the message