Comment by ineedtosleep
12 years ago
A couple more data points:
I'm running Fedora 19 and Arch on my main dev machines/VMs and as of this posting are considered up-to-date. Both are vulnerable:
[Fedora19] $ openssl version
OpenSSL 1.0.1e-fips 11 Feb 2013
[Arch] $ openssl version
OpenSSL 1.0.1f 6 Jan 2014
It does take time for these things to be tested and deployed. Regardless of severity of bug, distributions must test packages before sending them out to all their users.
It would be unfortunate if a new package were to be released immediately only to be soon masked/recalled due to unforeseen consequences.
Of note, the Gentoo package was bumped approximately 2 hours after the advisory was published.
To be clear, the Gentoo package is only in unstable. It hasn't reached stable yet. (https://bugs.gentoo.org/show_bug.cgi?id=507074)
Yeah, I haven't seen any new RPMs for RHEL/CentOS/Fedora yet. Kinda concerning, since I'd expect vendors to be given advance notice and the chance to prep updates to coincide with the announcement.
All my RHEL5 boxes are running 0.9.8, though, at least.
I've built RPMs for 1.0.1g for CentOS 6. Based of 1.0.1e source rpms. https://www.dropbox.com/sh/7s1fiuvfwma16ra/iSz3Jfh1o-
RHEL6 update announcement
https://rhn.redhat.com/errata/RHSA-2014-0376.html
Likewise for Ubuntu 13.10: OpenSSL 1.0.1e 11 Feb 2013
And the current beta of 14.04: OpenSSL 1.0.1f 6 Jan 2014
The Arch package is available in Testing. https://www.archlinux.org/packages/testing/i686/openssl/
F20 and F19 updates are on their way to the updates repo.
https://admin.fedoraproject.org/updates/openssl-1.0.1e-37.fc...
https://admin.fedoraproject.org/updates/openssl-1.0.1e-37.fc...
apt-get update && apt-get -t testing install openssl yields OpenSSL 1.0.1f on Debian sigh
Ubuntu (and I suppose Debian too), just released a fix in 13.10.
Not affected directly on Mac OS:
Unless you installed the macports version, which is 1.0.1f
Homebrew has updated to 1.0.1g since 6:00PM GMT. It's important to note that this isn't an issue unless you have an outward facing service that uses TLS and the brew/macports library
The MacPorts version has now been updated to 1.0.1g.