Gentoo Archives: gentoo-security

From: Jeremy Huddleston <eradicator@g.o>
To: phil@×××××.us
Cc: gentoo-security@l.g.o
Subject: [gentoo-security] Re: [gentoo-announce] Gentoo Linux Security Advisory 200403-03: Multiple OpenSSL Vulnerabilities
Date: Thu, 18 Mar 2004 05:32:28
Message-Id: 1079587929.9567.2424.camel@eradicator.outersquare.org
In Reply to: Re: [gentoo-security] Re: [gentoo-announce] Gentoo Linux Security Advisory 200403-03: Multiple OpenSSL Vulnerabilities by Phil Cryer
1 The 0.9.7 ebuilds should install 0.9.6 if it's on your system when the
2 ebuild runs? Are you using grp? Perhaps the binaries don't include
3 0.9.6, but my install did:
4
5
6 $ qpkg -I -v openssl
7 qpkdev-libs/openssl-0.9.7d *
8
9 $ qpkg -l openssl | grep lib
10 <snip>
11 /usr/lib/libssl.so.0.9.6
12 /usr/lib/libssl.so.0.9.7
13 /usr/lib/libssl.so -> libssl.so.0 1079583999
14 /usr/lib/libcrypto.so -> libcrypto.so.0 1079583999
15 /usr/lib/pkgconfig
16 /usr/lib/pkgconfig/openssl.pc
17 /usr/lib/libssl.so.0 -> libssl.so.0.9.7 1079583999
18 /usr/lib/libcrypto.so.0.9.6
19 /usr/lib/libcrypto.so.0.9.7
20 /usr/lib/libcrypto.so.0 -> libcrypto.so.0.9.7 1079583999
21 /usr/lib/libcrypto.a
22 /usr/lib/libssl.a
23 <snip>
24
25 --Jeremy
26
27 On Wed, 2004-03-17 at 21:26, Phil Cryer wrote:
28 > Piotr Kalinowski said:
29 > > It is indeed 0.9.6-0.9.7 update issue. You can emerge 0.9.6 now or
30 > > re-emerge
31 > > everything that uses ssl, so it would be linked against 0.9.7 instead of
32 > > 0.9.6. Start with python as it was already said.
33 >
34 > Thank you. For now I'm going to unmerge 0.9.7 and then emerge 0.9.6m. In
35 > the future if I want to update to 0.9.7 how can I tell what else I need to
36 > remerge for things to work? In other words, how do I know what needs ssl?
37 >
38 > P

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies