Page 1 of 1

Critical vulnerability in openssl

Posted: Thu Apr 10, 2014 6:48 pm
by imperio
Attention!
Discovered a critical security vulnerability in the openssl


The vulnerability is very serious

Solution:

CentOS

Code: Select all

yum update
service vesta restart
Ubuntu/Debian

Code: Select all

apt-get upgrade
service vesta restart
Validation service vulnerability
http://filippo.io/Heartbleed

Re: Critical vulnerability in openssl

Posted: Fri Apr 11, 2014 1:16 am
by nightstryke
A little late to the party aren't ya? I heard about this 2 days ago. Though it is a problem.

Re: Critical vulnerability in openssl

Posted: Wed May 14, 2014 10:36 pm
by osc2nuke
ok... even later , but i still get message that i have a vulnerable version running.


Server OS: Linux 2.6.32-358.6.2.el6.x86_64
HTTP Server: Apache/2.2.15 (CentOS)
PHP Version: 5.4.22 (Zend: 2.4.0)

OpenSSL support enabled
OpenSSL Library Version OpenSSL 1.0.0-fips 29 Mar 2010
OpenSSL Header Version OpenSSL 1.0.0-fips 29 Mar 2010

i did in putty:

Code: Select all

yum update
service vesta restart

Re: Critical vulnerability in openssl

Posted: Thu May 15, 2014 1:02 am
by osc2nuke
ok, problem is solved :)