[Pkg-openssl-devel] openssl (1.0.2~beta1-1) - Heartbleed

Ralph J.Mayer rmayer at nerd-residenz.de
Tue Jun 10 10:48:10 UTC 2014


Hi,

1.0.2.beta1 is still vulnerable to Heartbleed.

I know it's SID and OpenSSL has not released a newer version.

But, it's there in the repository and I got bitten.
And probably others will be bitten, too.

Is it possible to release a beta1-debian without the DTLS subsystem to
cover this?

If you want, I could open a bug for this.


Thx a lot for your work on Debian!


Best regards

Ralph



More information about the Pkg-openssl-devel mailing list