OpenSSL 嚴重安全性問題 Heartbleed - Linux

Jack avatar
By Jack
at 2014-04-08T12:32

Table of Contents


嚴重到有專屬網站 囧


http://heartbleed.com/



確認中槍的 distro

Debian Wheezy (stable), OpenSSL 1.0.1e-2+deb7u4
Ubuntu 12.04.4 LTS, OpenSSL 1.0.1-4ubuntu5.11
CentOS 6.5, OpenSSL 1.0.1e-15
Fedora 18, OpenSSL 1.0.1e-4
OpenBSD 5.3 (OpenSSL 1.0.1c 10 May 2012) and 5.4 (OpenSSL 1.0.1c 10 May 2012)
FreeBSD 8.4 (OpenSSL 1.0.1e) and 9.1 (OpenSSL 1.0.1c)
NetBSD 5.0.2 (OpenSSL 1.0.1e)
OpenSUSE 12.2 (OpenSSL 1.0.1c)


安全的

Debian Squeeze (oldstable), OpenSSL 0.9.8o-4squeeze14
SUSE Linux Enterprise Server


--

My Blog

http://rueiyuanlu.blogspot.com/

--
Tags: Linux

All Comments

James avatar
By James
at 2014-04-11T16:29
怎麼感覺最近常常聽到unix出這種包 冏
Ophelia avatar
By Ophelia
at 2014-04-15T15:23
好可怕 -.- 立刻更新
Andrew avatar
By Andrew
at 2014-04-20T02:39
難怪今天上完課回來打開就看到更新....
Charlie avatar
By Charlie
at 2014-04-23T15:40
archlinux呢OAO
Olive avatar
By Olive
at 2014-04-26T05:18
1.0.1.f 到底有沒有Orz
Caroline avatar
By Caroline
at 2014-04-27T20:54
https://www.openssl.org/news/secadv_20140407.txt
官方說有,不過實際上看 distro 有沒有開 heartbeat
Christine avatar
By Christine
at 2014-04-29T01:42
所以debian testing還得回去確認一下Orz
剛剛看是1.0.1f
Ingrid avatar
By Ingrid
at 2014-05-01T21:36
http://tinyurl.com/pr9aspx
Leila avatar
By Leila
at 2014-05-02T10:48
這種怪包我之前看到時第一個想法是NSA高手放進去的,裝成像
不小心寫錯的code,沒辦法,這包腫很大,很難不往這裏想
Robert avatar
By Robert
at 2014-05-05T23:56
謝啦,回去吃sid了
Hedda avatar
By Hedda
at 2014-05-10T11:36
Arch 今天終於升到 1.0.1g ,請更新吧
Emily avatar
By Emily
at 2014-05-14T03:54
https://launchpad.net/ubuntu/+source/openssl 已修
Kelly avatar
By Kelly
at 2014-05-15T03:20
MGA 4 今天剛剛修好
Ursula avatar
By Ursula
at 2014-05-16T20:11
openSUSE 13.1 不在名單裡面? 剛剛收到更新ㄟ...@@
Carol avatar
By Carol
at 2014-05-18T02:17
又,隔壁OS X自帶的0.9.8y看起來應該是安全的,只是很老舊
Olga avatar
By Olga
at 2014-05-20T00:07
名單僅供參考用 XD wheezy 也已經有 security update 了
Donna avatar
By Donna
at 2014-05-24T20:30
幹,中標了。
Dinah avatar
By Dinah
at 2014-05-27T12:05
樓上XD
Isla avatar
By Isla
at 2014-05-31T09:08
樓樓上XDDD
Damian avatar
By Damian
at 2014-05-31T12:04
wheezy今天又更新
Margaret avatar
By Margaret
at 2014-06-04T17:13
push
Rae avatar
By Rae
at 2014-06-06T03:30
Diffie-Hellman key exchange 還是有必要...
Oliver avatar
By Oliver
at 2014-06-10T17:00
真的有媒體報 NSA 兩年前已知 bug 存在而且加以利用
Leila avatar
By Leila
at 2014-06-11T20:05
雖然說 NSA 也發了稿否認啦
Kristin avatar
By Kristin
at 2014-06-16T01:05
#1JI89WVp (Gossiping) 中時新聞能信?
Damian avatar
By Damian
at 2014-06-20T07:12
說是德國程式設計師寫的;NSA說看報才知漏洞
Emma avatar
By Emma
at 2014-06-23T18:17
上個月不也有TLS的goto寫錯,會不會是ios爆炸後大家開始review
Emily avatar
By Emily
at 2014-06-26T00:38
kdjf 這不是協定的問題好嗎...
Hedy avatar
By Hedy
at 2014-06-29T05:49
https://access.redhat.com/site/announcements/781953
Redhat說它自家的website不用openssl,該不會早就防著NSA?
Sierra Rose avatar
By Sierra Rose
at 2014-07-04T01:19
應該不是不用openssl,應該是他們用的版本不是有bug的那些
Damian avatar
By Damian
at 2014-07-08T07:21
RHEL體系都還是openssl1.0 Heartbleed是1.0.1之後
Ula avatar
By Ula
at 2014-07-11T21:08
我再看了一遍,應該是樓上2位說的,之前看太快誤解意思,再加
Bennie avatar
By Bennie
at 2014-07-15T03:04
上快十年沒有Redhat家產品
Olga avatar
By Olga
at 2014-07-17T17:29
別說1.0了 現在也不少機器是用0.9.8呢www
Kumar avatar
By Kumar
at 2014-07-18T09:12
RH系的套件更版就只有慢而已,平常只會覺得麻煩,要手動
Zanna avatar
By Zanna
at 2014-07-19T07:21
找新版來換,難得爆炸的時候就會覺得穩定的舊版也不錯..XD
Joe avatar
By Joe
at 2014-07-22T09:32
要追新版本來就不該用RH系啊...
像Arch之類的多美好啊(笑

HackingThursday 固定聚會 (2014-04-10)

Christine avatar
By Christine
at 2014-04-07T12:04
通告網址: [http://www.hackingthursday.org/][1] * * * * 時間: 每週四晚上 19:30 至 22:00 ( 熱食供應至 20:00 ) * 地點: 伯朗咖啡 ( 建國店 ) * 地址: 台北市大安區建國南路一段 166 號 2 樓 * 鄰 ...

開久就當機(約一天)

Hardy avatar
By Hardy
at 2014-04-07T10:22
各位大大好,小弟是接觸LINUX家庭的菜鳥 目前在學習架設Fedora 16 提供 Apache+Mysql+PHP的服務 好不容易把功能都做出來了確發現一個問題 那就是and#34;很容易當機and#34; (大約一天 而且實際主機會連滑鼠都無法動) 我用預設的iptables 和 整個關閉SELinu ...

Ubuntu開機選單很多種是?

Zenobia avatar
By Zenobia
at 2014-04-07T01:05
在Win8電腦上 USB選安裝Ubuntu 將在Win8時新分割的磁區 先刪除再變更ext4分割 留幾G分割Swap 然後重啟 在用USB進入Ubuntu選試用不安裝 終端機安裝boot-repair sudo add-apt-repository ppa:yannubuntu/boot-repair su ...

用avconv上下翻轉3gp影片

Rosalind avatar
By Rosalind
at 2014-04-06T13:14
因為用手機拍的時候拿反了, 所以產生的影片是上下顛倒的, 也懶得裝其他軟體,就想用已經有的avconv來轉, 指令:avconv -i VID_20140406_100448.3gp -vf vflip slowboot.3gp 結果轉出來的影片是空的,terminal上也出現這樣一段紅字: Err ...

Nginx backlog設置

Caitlin avatar
By Caitlin
at 2014-04-06T01:40
目前使用Nginx搭配PHP-FPM架設網站, 遇到當瞬間流量飆高的時候, 很容易發生502 Bad Gateway的狀況, 目前Server已經針對kernel的相關參數做過調整, 也參考過很多網路文章做系統優化, 仍然還是持續發生502 Bad Gateway的狀況, 但就在今天意外調整了Ng ...