CVE-2018-0732

Started by Wyrm, July 19, 2018, 02:57:39 PM

Previous topic - Next topic
Hi,
I have done security audit on version 18.1.12 and there is security vulnerabilty:

***GOT REQUEST TO AUDIT SECURITY***
vulnxml file up-to-date
libressl-2.6.5 is vulnerable:
OpenSSL -- Client DoS due to large DH parameter
CVE: CVE-2018-0732
WWW: https://vuxml.freebsd.org/freebsd/c82ecac5-6e3f-11e8-8777-b499baebfeaf.html

1 problem(s) in the installed packages found.
***DONE***

Versions on box:
OPNsense 18.1.12-amd64
FreeBSD 11.1-RELEASE-p11
LibreSSL 2.6.5

Is it Ok, or there will be some patch ?

Thanks for reply...

Hi,

LibreSSL 2.6.5 is not vulnerable. There is an error in the FreeBSD database and the ports security team did not merge the fix:

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=229037


Cheers,
Franco