fedora-cloud / docker-brew-fedora

MIT License
182 stars 46 forks source link

CVE-2015-4000 ("Logjam") #16

Closed tianon closed 4 years ago

tianon commented 9 years ago

https://www.openssl.org/blog/blog/2015/05/20/logjam-freak-upcoming-changes/ https://weakdh.org/ https://bugzilla.redhat.com/show_bug.cgi?id=1224447

Reading that report it sounds like the fixes have dropped already, and might just be waiting on mirror propagation? Am I reading that right?

Once the fixes are available, updated rootfs tarballs would be :+1:. :heart:

lsm5 commented 9 years ago

hmm, yup, looks like I gotta update the f20 image. Will send that one out in a bit. Though I was hoping we could just get rid of f20 given that it will now be end-of-life soon (if not already)

tianon commented 9 years ago

Definitely no problem with getting rid of f20 if it's EOL! :+1:

tianon commented 9 years ago

https://fedoraproject.org/wiki/End_of_life

Doesn't seem like we're quite there yet, though. :confused:

lsm5 commented 9 years ago

iirc, f20 will continue to get security updates till about 1 month after f22 release and after that we can completely forget about it, but gotta confirm that.

siddharthvipul commented 4 years ago

issue related to the EOL versions. Please reopen if you notice this in newer images