Gentoo Archives: gentoo-server

From: Jeff Smelser <tradergt@×××××××.org>
To: phil@×××××.us
Cc: gentoo-server@l.g.o
Subject: [gentoo-server] Re: [gentoo-security] Re: [gentoo-announce] Gentoo Linux Security Advisory 200403-03: Multiple OpenSSL Vulnerabilities
Date: Thu, 18 Mar 2004 05:20:57
Message-Id: 200403172320.47335.tradergt@smelser.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On Wednesday 17 March 2004 11:11 pm, Phil Cryer wrote:
5 > Troy Farrell said:
6 > > Phil, I see one problem though I'm not sure I have the solution.
7 > > The 'emerge sync' error is a python traceback. A temporary fix (enough
8 > > to get
9 > > it working long enough to fix it) might be to soft link your
10 > > libssl.so.0.9.7 to
11 > > libssl.so.0.9.6. You need to re-emerge python because of the +ssl USE
12 > > flag. I
13 > > can't say what the 'CANNOT IMPORT FTPLIB' error means.
14 >
15 > Troy
16 > Thanks for your quick response. After pouring through the forums, I did
17 > the portage rescue deal, did ldconfig, nothing was working for me.
18 > Eventually I did this:
19 >
20 > cp /usr/lib/libssl.so.0.9.7 /usr/lib/libssl.so.0.9.6
21 >
22 > and now I can emerge and all my apps run (I could run Firefox, but not
23 > xfce4, and any other gtk based thing, plus on my server everything had
24 > ground to a halt too!)
25 >
26 > so, now it's 'working' but not fixed. when I try to do ssh it fails with:
27 >
28 > ssh jorge -l root
29 > OpenSSL version mismatch. Built against 9060bf, you have 90704f
30 >
31 > I'm unsure what to do next, and I don't want to break things any further.
32 > Also, I'm concerned that a simple security upgrade messed things up so
33 > much (that's all I did was emerge openssl) perhaps I should have done the
34 > updated 0.9.6 instead of the 0.9.7? If that's the case, maybe I can
35 > unmerge 0.9.7 and re-emerge 0.9.6? or can I make 0.9.7 work?
36
37 You didn't update from 9.6 to 9.7.. OR, you didn't run the revdep-rebuild like
38 you were suppose to.. IN the ebuild, it tells you to run to revdep-rebuild
39 commands to fix that..
40
41 Jeff
42 - --
43 Good looks aren't everything. Loose morals count, too.
44 -----BEGIN PGP SIGNATURE-----
45 Version: GnuPG v1.2.4 (GNU/Linux)
46
47 iD8DBQFAWTGvld4MRA3gEwYRAkHHAKDNjwMhB4fq+qTcHortMY+DcWF7jQCeMqXL
48 Uqo6U38TymlVk350XopxUVk=
49 =i9zl
50 -----END PGP SIGNATURE-----