New user's registration have been closed due to high spamming and low trafic on this forum. Please contact forum admins directly if you need an account. Thanks !
does this bug affect us?
-
- Posts: 904
- Joined: 09 Oct 2009, 18:49
Re: does this bug affect us?
From the linked page:
So, no?
From my up to date B3:OpenSSL 0.9.8 branch is NOT vulnerable
Code: Select all
$ apt-cache policy openssl
openssl:
Installed: 0.9.8o-4squeeze14
Candidate: 0.9.8o-4squeeze14
Version table:
*** 0.9.8o-4squeeze14 0
500 http://ftp.se.debian.org/debian/ squeeze
/main armel Packages
600 http://b3.update.excito.org/ upstream_sq
ueeze/main armel Packages
100 /var/lib/dpkg/status
Re: does this bug affect us?
That was my conclusion as well when I saw the bug. Maybe sometimes being on a very old version is a good thing, rightRandomUsername wrote:So, no?

/Daniel
Re: does this bug affect us?
Not always. Remember the PHP CGI bug?
As for openssl, we don't know if the heartbeat bug was introduced by fixing another bug or introducing a new feature. To really know whether 0.9.8 is safer than 1.0.x one should plough through the changelogs.
As for openssl, we don't know if the heartbeat bug was introduced by fixing another bug or introducing a new feature. To really know whether 0.9.8 is safer than 1.0.x one should plough through the changelogs.
-
- Posts: 904
- Joined: 09 Oct 2009, 18:49
Re: does this bug affect us?
I've been playing with some of the tools for testing this vulnerability. So far, the only vulnerable site I've found is this one!
[EDIT]There's an online checker for anyone who's interested: filippo.io/Heartbleed/
Code: Select all
$ ./heartbleeder forum.excito.net
VULNERABLE - forum.excito.net:443 has the heartbeat extension enabled and is vulnerable to CVE-2014-0160
Re: does this bug affect us?
Yes, we have gone through all our servers now and the only one affected was this forum (patched now). Since we cannot guarantee anything, you might want to consider changing your passwords here.
/Johannes (Excito co-founder a long time ago, but now I'm just Johannes)