Entware-for-kernel-3x / Entware-ng-3x

Ultimate repo for embedded devices
GNU General Public License v2.0
42 stars 5 forks source link

OpenSSL security #65

Closed zd59 closed 6 years ago

zd59 commented 6 years ago

Package: libOpenSSL

Current version is 1.0.2n and insecure.

Will you upgrade libOpenSSL library to a current version (1.1.0) to cover up a security threat? OpenSSL is one of the most essential part of routers, so it must be secure. As of that fact consider that as high priority.

Thank you.

zyxmon commented 6 years ago

openssl volnerabilites can be found in 1.1.0 and 1.0.2 branches - https://www.openssl.org/news/vulnerabilities.html We will switch to another branch after openwrt upgrades openssl.