4 ms·
OpenSSL 1.0.1f is completely unsupported by the OpenSSL project, as that advisory points out: Support for version 1.0.1 ended on 31st December 2016. Support fo
by lfam 10y ago
OpenSSL 1.0.1f is completely unsupported by the OpenSSL project, as that advisory points out:
Support for version 1.0.1 ended on 31st December 2016. Support for versions
0.9.8 and 1.0.0 ended on 31st December 2015. Those versions are no longer
receiving security updates.
Since 1.0.2 is not vulnerable, it seems unlikely that the bug would be in 1.0.1.
- paulddraper 10y agoUbuntu 14.04 is LTS though, so they'll be updating to a supported version of OpenSSL, just as they've done with, say, OpenJDK ( https://bugs.launchpad.net/trusty-backports/+bug/1368094 https://bugs.launchpad.net/trusty-backports/+bug/1368094 ). </s> I love Ubuntu; the "LTS" part is a bit of a joke.
- compuguy 10y agoThis happened before with 12.04 LTS. They never back-ported a newer version of OpenSSL.
- kbenson 10y agoI'm not sure if it's just poor wording, but that way you stated that makes it seem like you don't know what backporting is. Backporting[1] is not providing a newer version of the application/library in question, it's taking the fix and making it work on the older version. A cursory look at the Ubuntu security advisories page shows that they have back-ported OpenSSL for both 14.04 LTS and 12.04 LTS. There's one from a few weeks ago for both[2], and there are many more that have been done. 1: https://access.redhat.com/security/updates/backporting https://access.redhat.com/security/updates/backporting 2: https://www.ubuntu.com/usn/usn-3181-1/ https://www.ubuntu.com/usn/usn-3181-1/
- kikoreis 10y agoI noted above that the nomenclature is inconsistent between Ubuntu and RHEL. But you are right on the money with regards to the fix in precise.
- compuguy 10y agoI've seen ubuntu backport fixes and rarely backport packages from a newer Ubuntu/Debian release. As you said, the nomenclature for backport is confusing.
- kklimonda 10y agoWhy is it a joke? It has always been a case that Canonical will backport security patches and critical bugfixes, rather than updating the entire package to the latest upstream version. On the other hand, Ubuntu Backports is community project, and your snarkiness is unwarranted - as long as no one cares enough to backport and keep maintaining the backport, it won't be done.
- kbenson 10y agoThat not backporting, that's a package upgrade request. Backporting[1] is something different, and applies to features and bug fixes being ported back to older versions of a product, not providing an upgraded package for an older product. All the enterprise class distributions backport (for good reason). Some also provide the occassional package upgrades (such as those that roll out at RHEL point-releases). 1: https://access.redhat.com/security/updates/backporting https://access.redhat.com/security/updates/backporting
- kikoreis 10y agoIn Ubuntu terms a backport is when a newer version of a package is made available in an existing release. With few exceptions (see MicroReleaseExceptions) versions of packages in a distro release are not updated, which is why the backports pockets exist. We certainly provide security updates for packages in main for the LTS lifetime.
- kbenson 10y agoThat's unfortunate, as there has been accepted terminology that differentiates those concepts for quite a while in the enterprise distribution space, likely predating Ubuntu's existence. Backports as you describe them here are referred to as "rebasing" in RHEL's parlance. I understand where the difference comes from though, Debian. The problem is that Debian serves a different need, and is not really an "enterprise" distro. That's not to imply it isn't a quality distribution, but their purposes are not necessarily aligned with the needs of organizations which may be managing hundreds or more systems all at once. Debian "backports" newer packages from testing to to current to deal with needed fixes, while enterprise distributions "backport" the patches to make sure the package behavior doesn't inadvertently change due to some other changes in the package during the time since it was first included. Ubuntu's beginnings as an offshoot of Debian show here, but that's where there's a disconnect between the terminology they use and that of most other distributions that target the enterprise (which admittedly Ubuntu only does partially). I can't really blame Ubuntu for their use of the terminology, since it does have historical precedence for them, and they are't even entirely an enterprise distro (by which I mean they also target desktop usage heavily, compared to RHEL which only goes as far that direction as to target workstations, and somewhat halfheartedly IMO).
- sdeziel 10y agoOpenSSL is in "main" and as such, it is supported by Canonical for the whole lifetime of the LTS. Upstream dropping support doesn't change that, it simply means that Canonical security team will be backporting patches themselves. https://people.canonical.com/~ubuntu-security/cve/pkg/openssl.html https://people.canonical.com/~ubuntu-security/cve/pkg/openss...
- alyandon 10y agoThe sad thing is no one was asking Ubuntu to rebuild all the system dependencies against OpenJDK 8. Developers just wanted the package to be available for installing. The extra icing on the cake? They removed OpenJDK 7 from 16.04 despite it still being supported. :-/
- compuguy 10y agoWait, why?