volumio / RootFS-RaspberryPI

Volumio's Debian ARMv6 Filesystem for RaspberryPI
26 stars 18 forks source link

Heartbleed Vulnerability #6

Open learntofly83 opened 8 years ago

learntofly83 commented 8 years ago

RootFS-RaspberryPI/usr/bin/openssl is vulnerable to heartbleed.

Fix, upgrade to OpenSSL 1.0.1g as a minimum


In the context of this test, our RPI is the client and our PC the sever:

https://github.com/Lekensteyn/pacemaker.git


volumio@volumio:~/tests/pacemaker$ which openssl /usr/bin/openssl volumio@volumio:~/tests/pacemaker$ sudo apt-cache policy openssl openssl: Installed: 1.0.1e-2+rpi1 Candidate: 1.0.1k-3+deb8u1 Version table: 1.0.1k-3+deb8u1 0 500 http://mirrordirector.raspbian.org/raspbian/ jessie/main armhf Packages *\ 1.0.1e-2+rpi1 0 100 /var/lib/dpkg/status

learntofly83 commented 8 years ago

You are however ok for shellshock at least on rpi