OPNsense Forum
Archive => 18.1 Legacy Series => Topic started by: Wyrm on July 19, 2018, 02:57:39 pm
-
Hi,
I have done security audit on version 18.1.12 and there is security vulnerabilty:
***GOT REQUEST TO AUDIT SECURITY***
vulnxml file up-to-date
libressl-2.6.5 is vulnerable:
OpenSSL -- Client DoS due to large DH parameter
CVE: CVE-2018-0732
WWW: https://vuxml.FreeBSD.org/freebsd/c82ecac5-6e3f-11e8-8777-b499baebfeaf.html
1 problem(s) in the installed packages found.
***DONE***
Versions on box:
OPNsense 18.1.12-amd64
FreeBSD 11.1-RELEASE-p11
LibreSSL 2.6.5
Is it Ok, or there will be some patch ?
Thanks for reply...
-
Hi,
LibreSSL 2.6.5 is not vulnerable. There is an error in the FreeBSD database and the ports security team did not merge the fix:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=229037
Cheers,
Franco