[BlueOnyx:15149] Re: OpenSSL (CenOS-6.5/SL-6.5) CVE-2014-0160

Randy Smith forhire at lewiscounty.com
Wed Apr 9 03:22:38 -05 2014


> I follow the update procedure below but after a reboot the 'openssl 
> version' gives me OpenSSL 1.0.1e-fips 11 Feb 2013

I have the same question. Yum auto updated to 1.0.1e this morning.

Apr 08 06:00:22 Updated: openssl-1.0.1e-16.el6_5.7.x86_64

When I tested using http://filippo.io/Heartbleed/ it indicated no issue. 

All good, www.domain.com:443 seems not affected! 

Was this older version just recompiled with the handshake removed
(-DOPENSSL_NO_HEARTBEATS)? I expected the version update to be 1.0.1g.

Thanks,

Randy



More information about the Blueonyx mailing list