We probably don't need to worry this time: https://ma.ttias.be/openssl-cve-2015-1793-man-middle-attack/ "The vulnerability appears to exist only in OpenSSL releases that happened in June 2015 and later. That leaves a lot of Linux distributions relatively safe, since they haven't gotten an OpenSSL update in a while. Red Hat, CentOS and Ubuntu appear to be entirely unaffected by this vulnerability, since they had no Op…
Christ, what a mess of a project. They inserted this after their big promise to do better after heartbleed? No wonder distros take their time moving to a new version. I really hope one of the alternative SSL libraries get picked up by the major distros. This is embarrassing, especially for those of us who have to justify FOSS in our environment. LibreSSL looks promising. Hopefully competition will mean better outcome…
It's not the number of bugs that matters, or even the fact that new bugs get introduced over time - rather it's the severity of the bugs, how rapidly the bugs are realized, and ultimately how fast they are dealt with.
In this case, it appears to have been a pretty rapid resolution - ie. about 1 month from it being introduced, realized, and fixed.
A lot of folks like to lean on LibreSSL and cite "supposed problems" with OpenSSL, just as you have done now. This is a naive approach -- LibreSSL took OpenSSL, cannibalized and gutted it, and all sorts of new, untested, un-vetted code injected. OpenSSL was written largely by crypto specialists, where LibreSSL is mostly a bunch of grumbling developers, with little to no prior crypto experience.
There's a reason the world is not jumping on LibreSSL just yet. There's a reason foundations outside of the LibreSSL home (OpenBSD) such as the Core Infrastructure Foundation have not backed it -- it's simply not ready, is very unproven, and won't be for a long, long time, if ever.
Give OpenSSL a break. It works far better than nay-sayers want to let on, and has done so for almost 2 decades.