OPNsense Forum

Archive => 22.7 Legacy Series => Topic started by: chemlud on November 01, 2022, 11:15:58 AM

Title: openSSL 3.0.7 - any timelines yet?
Post by: chemlud on November 01, 2022, 11:15:58 AM
https://www.computerweekly.com/news/252526709/Prepare-today-for-potentially-high-impact-OpenSSL-bug

...?
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: ProximusAl on November 01, 2022, 12:19:01 PM
It's my understanding that OPNSense uses OPENSSL 1.1.1 so it's not affected.
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: seed on November 01, 2022, 01:08:15 PM
root@OPNsense:~ # openssl version
OpenSSL 1.1.1o-freebsd  3 May 2022


Edit:

Versions       OPNsense 22.7.6-amd64
                   FreeBSD 13.1-RELEASE-p2
                   OpenSSL 1.1.1q 5 Jul 2022
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: almodovaris on November 01, 2022, 01:25:08 PM
root@OPNsense:~ # /usr/local/bin/openssl version
OpenSSL 1.1.1q  5 Jul 2022
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: chemlud on November 01, 2022, 02:30:31 PM
So it's consensus that only 3.x is vulnerable? Any source for that conclusion yet?
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: ProximusAl on November 01, 2022, 02:53:51 PM
Erm...yes....the very hyperlink you posted above?
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: Patrick M. Hausen on November 01, 2022, 02:54:51 PM
@chemlud - the article you linked in your initial post?
QuoteWhat is known is that the incoming vulnerability only affects 3.0.x versions of OpenSSL

What's all the fuss about? OPNsense does not use this particular product, why should Deciso or the OPNsense team publish anything at all?
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: chemlud on November 01, 2022, 04:52:53 PM
I asked two questions, I don't see any "fuss". Nice to know that sense is not affected...
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: RamSense on November 01, 2022, 06:25:45 PM
jup indeed.
The only strange thing I found was that opnsense gui states:
OPNsense 22.7.6-amd64
FreeBSD 13.1-RELEASE-p2
OpenSSL 1.1.1q 5 Jul 2022

and the terminal window:
openssl version
OpenSSL 1.1.1o-freebsd

so why is the gui claiming version 1q and terminal gives back 1o?
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: Deku on November 01, 2022, 06:48:16 PM
What about LibreSSL?  My OpnSense is currently on LibreSSL 3.3.6.  I see version 3.6.1 was just released but not sure if this vuln applies.
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: Fright on November 01, 2022, 07:14:56 PM
@RamSense
Quoteso why is the gui claiming version 1q and terminal gives back 1o?
widget shows ports version (/usr/local/bin/openssl version)
shell shows base (OS) version (/usr/bin/openssl version)

@Deku
no
https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
openssl only.
3.0 branch only
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: RamSense on November 01, 2022, 08:40:16 PM
@Fright, ah, thanks for explaining!
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: almodovaris on November 01, 2022, 10:25:06 PM
openssl 1.1.1s has been published.
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: ibb27 on November 02, 2022, 09:18:21 AM
Quote from: Deku on November 01, 2022, 06:48:16 PM
What about LibreSSL?  My OpnSense is currently on LibreSSL 3.3.6.  I see version 3.6.1 was just released but not sure if this vuln applies.
https://marc.info/?t=166716388700001&r=1&w=2
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: chemlud on November 02, 2022, 09:55:36 AM
Is LibreSSL still functional with 22.7.x? It was my understanding that support of LibreSSL would be deleted with 22.7 (but for the last months I didn't have the ttime to follow up) so I switched to openSSL before updating to 22.7...

Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: franco on November 02, 2022, 12:45:21 PM
LibreSSL will disappear with 23.1. Right now it's still available but ports breakage continues regularly.

OpenSSL 1.1.1s will be in 22.7.7 which is scheduled for tomorrow (but for other reasons than OpenSSL).


Cheers,
Franco
Title: Re: openSSL 3.0.7 - any timelines yet?
Post by: chemlud on November 02, 2022, 01:15:15 PM
Thanks for clarification!