OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.7 Legacy Series »
  • openssl-1.0.2t,1 is vulnerable
« previous next »
  • Print
Pages: [1]

Author Topic: openssl-1.0.2t,1 is vulnerable  (Read 1487 times)

bruci3

  • Newbie
  • *
  • Posts: 20
  • Karma: 0
    • View Profile
openssl-1.0.2t,1 is vulnerable
« on: December 31, 2019, 11:12:50 pm »
Hi all,

I just updated my Opnsense to latest version.

OPNsense 19.7.8-amd64
FreeBSD 11.2-RELEASE-p16-HBSD
OpenSSL 1.0.2t 10 Sep 2019

I got this when running security audit:

***GOT REQUEST TO AUDIT SECURITY***
vulnxml file up-to-date
openssl-1.0.2t,1 is vulnerable:
OpenSSL -- Overflow vulnerability
CVE: CVE-2019-1551
WWW: https://vuxml.FreeBSD.org/freebsd/d778ddb0-2338-11ea-a1c7-b499baebfeaf.html

1 problem(s) in 1 installed package(s) found.
***DONE***

Should I be concerned? If so, is there anything I can do about it?
Logged

fabian

  • Hero Member
  • *****
  • Posts: 2770
  • Karma: 199
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: openssl-1.0.2t,1 is vulnerable
« Reply #1 on: January 01, 2020, 12:09:49 am »
Looks like it is only triggered on key generation and only when generating weak keys.
Logged

bruci3

  • Newbie
  • *
  • Posts: 20
  • Karma: 0
    • View Profile
Re: openssl-1.0.2t,1 is vulnerable
« Reply #2 on: January 01, 2020, 12:42:39 am »
Thanks for the prompt reply.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 14333
  • Karma: 1242
    • View Profile
Re: openssl-1.0.2t,1 is vulnerable
« Reply #3 on: January 07, 2020, 02:31:25 pm »
Guys, please don't post vulnerability reports. We do all get the same report and we already work on inclusion whether you've seen it or not.  ;)

The report is solely for you in three separate ways:

1. You know a security bug was found in the software and somebody is/was working on a fix.
2. You know the details to be able to mitigate the issue if possible.
3. You know an OPNsense update is coming eventually to address this.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.7 Legacy Series »
  • openssl-1.0.2t,1 is vulnerable
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2