[packman] PMBS vulnerable to Heartbleed

Joachim Schrod jschrod at acm.org
Tue Apr 15 02:58:58 CEST 2014


On 04/14/14 15:54, Stefan Botter wrote:
> On Mon, 14 Apr 2014 07:45:59 -0500
> Malcolm <malcolmlewis at cableone.net> wrote:
> 
>> Hi
>> I'm assuming it's just the certificate?
>> 
>> Via https://addons.mozilla.org/en-US/firefox/addon/heartbleed-checker/
>> 
>> http://paste.opensuse.org/414fd0fe
>> 
>> And then;
>> 
>> https://www.ssllabs.com/ssltest/analyze.html?d=pmbs.links2linux.de
>> 
> 
> Yes, I know.
> PMBS runs openSUSE 12.2, and there are no security updates anymore.
> I am testing the update to 13.1 and OBS 2.5.1 right now on a different
> machine, but so far no smooth update seams to be possible.
> 
> I asked Marc for a new certificate already, but without an updates
> openssl lib this is not urgent.

Have you tried one of the home-based updated to (lib)openssl that
are available on OBS? E.g., from home:Simmphonie?

I've used them with great success. (Some of them don't play well
with Ruby, but AFAICS Ruby ain't used here.)

	Joachim

-- 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Joachim Schrod, Roedermark, Germany
Email: jschrod at acm.org





More information about the Packman mailing list