Gentoo Archives: gentoo-security

From: Phil Cryer <phil@×××××.us>
To: gentoo-security@l.g.o
Subject: [gentoo-security] Re: [gentoo-announce] Gentoo Linux Security Advisory 200403-03: Multiple OpenSSL Vulnerabilities
Date: Thu, 18 Mar 2004 05:36:31
Message-Id: 32874.192.168.0.7.1079588174.squirrel@192.168.0.7
In Reply to: [gentoo-security] Re: [gentoo-announce] Gentoo Linux Security Advisory 200403-03: Multiple OpenSSL Vulnerabilities by Jeremy Huddleston
1 Jeremy Huddleston said:
2 > The 0.9.7 ebuilds should install 0.9.6 if it's on your system when the
3 > ebuild runs? Are you using grp? Perhaps the binaries don't include
4 > 0.9.6, but my install did:
5
6 Interesting, I'm not sure what went wrong for me. What I did to fix
7 things was unmerged 0.9.7 -> re-emerged 0.9.6m and now I can use SSH
8 again. Here's my output:
9
10 hector lib # qpkg -I -v openssl
11 dev-libs/openssl-0.9.6m *
12 hector lib # qpkg -l openssl | grep lib
13 dev-libs/openssl-0.9.6m *
14 /usr/share/man/man3/SSL_library_init.3.gz
15 /usr/lib
16 /usr/lib/libssl.so.0 -> libssl.so.0.9.6
17 /usr/lib/libcrypto.so.0 -> libcrypto.so.0.9.6
18 /usr/lib/libcrypto.so.0.9.6
19 /usr/lib/libssl.so.0.9.6
20 /usr/lib/libcrypto.a
21 /usr/lib/libssl.so -> libssl.so.0
22 /usr/lib/libssl.a
23 /etc/ssl/lib
24 /usr/lib/libcrypto.so -> libcrypto.so.0
25
26 Does anything there look funny?
27
28 Also, thanks to all for the quick replies, when things went south I had
29 email, but no Xchat for IRC, so I didn't know what I was going to do.
30
31 P
32 --
33 http://lefttochance.com/
34
35 --
36 gentoo-security@g.o mailing list