If you're using OpenSSL 1.0.1, upgrade to 1.0.1c

10 May
2012
10 May
'12
10:35 p.m.
Hi, all! If you are using any version of openssl 1.0.1, 1.0.1a, or 1.0.1b, you should know that it's affected by a recent security advisory: https://www.openssl.org/news/secadv_20120510.txt If I am reading the diffs for this bug right, it looks like it would attacker to crash a server remotely. To avoid that, I'd recommend that all Tor nodes running any version of OpenSSL 1.0.1 should upgrade to 1.0.1c. Non-1.0.1 version of OpenSSL have this bug in their DTLS implementations, but Tor doesn't use DTLS. We'll try to get new packages out soon. yrs, -- Nick
4756
Age (days ago)
4756
Last active (days ago)
0 comments
1 participants
participants (1)
-
Nick Mathewson