oss-sec mailing list archives

Re: Other instances of CVE-2014-0160 - mod_spdy from Google


From: Arrigo Triulzi <arrigo () alchemistowl org>
Date: Wed, 9 Apr 2014 08:00:44 +0200

On Apr 9, 2014, at 05:59, Kurt Seifried <kseifried () redhat com> wrote:
So it appears there are projects that statically compile OpenSSL into
their software, one example:

Note that OpenVPN has also advertised on Twitter that they too have released a new version with a patch for Heartbleed. 
Most architectures ship with OpenVPN dynamically linked but they do distribute with their own private copy.

Arrigo

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail


Current thread: