Live data from Hacker News

OpenSSL Security Advisory

openssl.org

11–20 of 142 posts

Re: OpenSSL Security Advisory

#15
Interesting part is that the bug was introduced in the latest versions and has been fixed by the person who inserted it :-)

Bug added: https://github.com/openssl/openssl/commit/da084a5ec6cebd67ae...

Bug removed: https://github.com/openssl/openssl/commit/2aacec8f4a5ba1b365...

Although that's just the committer: https://twitter.com/agl__/status/619129579580469248

Re: OpenSSL Security Advisory

#19
post #8

Debian stable/oldstable is not affected. Only in unstable: https://security-tracker.debian.org/tracker/CVE-2015-1793

Well on Ubuntu I see nothing yet... http://www.ubuntu.com/usn/trusty/ I do not know if this is good or bad :(

http://people.canonical.com/~ubuntu-security/cve/2015/CVE-20...

Re: OpenSSL Security Advisory

#20

I've got a few sites using OpenSSL certs; do I need to do anything?

Unless you are using client side certificates, this one is not your problem. But everybody must upgrade their browsers ASAP.

Is that right? My reading of it is that this affects all cases where you verify the certificate
Post reply on HN