38 ms·
I suppose this is the "clear your schedule and be prepared to patch the entire world" version?
by m_eiman 4y ago
I suppose this is the "clear your schedule and be prepared to patch the entire world" version?
- datalopers 4y agoOpenSSL 3.x has a fairly small install base
- input_sh 4y agoLots of distros don't use v3 yet and are not affected. This is definitely far from Heartbleed level of catastrophe.
- TheRealDunkirk 4y agoFeh. I just upgraded my production and staging machines to Ubuntu 22, which no longer have v1, and which breaks compiling older (but still maintained) versions of Ruby. Everything is still running, but this change caught me flatfooted. I groused about Ubuntu, and someone told me that Fedora has also changed over. You say "lots" of distro's haven't. Which ones? (And, sure, I can already assume Debian stable, since that runs 7 years behind everything else, but what else?)
- macintux 4y agoThis is a good overview of what’s vulnerable: https://github.com/NCSC-NL/OpenSSL-2022/blob/main/software/README.md https://github.com/NCSC-NL/OpenSSL-2022/blob/main/software/R...
- deleted 4y ago[deleted]
- input_sh 4y agoI'm oversimplifying it a bit, but anything that hasn't reached stable this year is still using v1.1.1 (and therefore unaffected). Ubuntu v22.04 is vulnerable, but any before it is not. Debian is good (except bookworm which is currently in testing), Fedora (<36) is good, RHEL/CentOS (<9), Arch... So on top of being not as serious as Heartbleed, servers that are a bit longer in operation (but still well within their support cycle) don't need patching. https://github.com/NCSC-NL/OpenSSL-2022/tree/main/software https://github.com/NCSC-NL/OpenSSL-2022/tree/main/software EDIT just to add this quote from their blog post (https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/ https://www.openssl.org/blog/blog/2022/11/01/email-address-o...): > We did release an update to OpenSSL 1.1.1, namely 1.1.1s, also on 1st November 2022, but this is a bug fix release only and does not include any security fixes.
- bscphil 4y ago> You say "lots" of distro's haven't. Which ones? Surprisingly enough, Arch Linux, a rolling release distro, still hasn't. It's a real mixed bag.
- phonepostingsux 4y agoNeither has Gentoo, unless you unmasked 3.0 yourself.
- Sohcahtoa82 4y agoIn addition to very few distros using OpenSSL 3, your server is only affected if you do client certificate verification, which is exceptionally rare for public internet servers. As a client, you're only affected if you connect to a malicious server.
- ignaloidas 4y agoCould in theory be utilized to move laterally in networks where client TLS is used for authentication, which I see used sometimes.