Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

9.313003 GA Released

Up2Date 9.313003 package description:

Remark:
 System will be rebooted

News:
 Security Update

Bugfixes:
 Fix [35213]: OpenSSL security update 1.0.1o
 Fix [35235]: RED: Update OpenSSL

RPM packages contained:
 libaio-0.3.109-0.1.46.1252.g512b2a5.rb1.i686.rpm 
 libopenssl1_0_0-1.0.1k-0.200389443.g74553b7.rb3.i686.rpm
 libopenssl1_0_0_httpproxy-1.0.1k-0.200389443.g74553b7.rb3.i686.rpm
 libreadline5-5.2-147.22.1.1850.g512b2a5.rb1.i686.rpm
 bash-3.2-147.22.1.1850.g512b2a5.rb1.i686.rpm     
 mdadm-3.2.6-0.19.9.1251.g512b2a5.rb1.i686.rpm     
 openssl-1.0.1k-0.200389443.g74553b7.rb3.i686.rpm 
 red-firmware2-4013-0.g85b9aa7.noarch.rpm         
 timezone-2014g-0.3.1.1849.g512b2a5.rb1.i686.rpm   
 ep-chroot-httpd-9.30-22.g3d9de75.noarch.rpm       
 chroot-httpd-2.4.12-1.g70fba59.rb1.i686.rpm       
 ep-release-9.313-3.noarch.rpm


This thread was automatically locked due to age.
Parents
  • @Jim:  Thanks, did some further research on CVE-2015-4620.  This is only an issue when using DNSSEC validation, which is turned off by default and not used by many customers.  The fix might be in 9.314, which should be released this next week.  If you have a paid license, open up a support case and they should be able to tell you for certain, with a little digging.  The more paid users who open up cases on an issue, the higher priority the fix gets.  [:)]
    __________________
    ACE v8/SCA v9.3

    ...still have a v5 install disk in a box somewhere.

    http://xkcd.com
    http://www.tedgoff.com/mb
    http://www.projectcartoon.com/cartoon/1
Reply
  • @Jim:  Thanks, did some further research on CVE-2015-4620.  This is only an issue when using DNSSEC validation, which is turned off by default and not used by many customers.  The fix might be in 9.314, which should be released this next week.  If you have a paid license, open up a support case and they should be able to tell you for certain, with a little digging.  The more paid users who open up cases on an issue, the higher priority the fix gets.  [:)]
    __________________
    ACE v8/SCA v9.3

    ...still have a v5 install disk in a box somewhere.

    http://xkcd.com
    http://www.tedgoff.com/mb
    http://www.projectcartoon.com/cartoon/1
Children
No Data