Re: [openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-23 Thread Rainer M. Canavan
On Jul 22, 2014, at 09:17 , Venkata Golla venkata.go...@eai.ae wrote: Dear, We have already contacted with OS vendor (Oracle Linux) and Symantec (SSL certificate vendor). They both said, it is out of their scope. And we tried to install by following README; unfortunately it's not working.

RE: [openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-22 Thread Venkata Golla via RT
10:43 PM To: Venkata Golla Cc: openssl-dev@openssl.org Subject: [openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590) openssl does not distribute RPM's or pre-built binaries; contact your vendor if you can't build from source. If you want to build from source, please see

RE: [openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-22 Thread Venkata Golla
10:43 PM To: Venkata Golla Cc: openssl-dev@openssl.org Subject: [openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590) openssl does not distribute RPM's or pre-built binaries; contact your vendor if you can't build from source. If you want to build from source, please see

RE: [openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-22 Thread Salz, Rich
Where did you get your SSL package? Did it come with the OS? If so, then ask them for an update. If not, then where did you get it? Contact them. If you built it internally, you'll have to learn or buy expertise. -- Principal Security Engineer, Akamai Technologies, Cambridge, MA IM:

[openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-22 Thread Matt Caswell via RT
If you originally obtained your copy of OpenSSL in binary form (such as from your OS vendor), then please get hold of the latest copy from them. If you originally obtained your copy of OpenSSL in source form then you will need to build a new version from the latest release on the OpenSSL website.

[openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-21 Thread Venkata Golla via RT
Dear Team, As per the below trail mail we are trying to upgrade the open SSL version from OpenSSL 0.9.8 to 0.9.8za on oracle Linux 5.7 version. We have downloaded the tar file (openssl-0.9.8za.tar.gz) for the upgrade. But, we are not able install for the same. Could you please provide us the

[openssl.org #3467] FW: Critical vulnerabilities found (#8083-432678597-2590)

2014-07-21 Thread Rich Salz via RT
openssl does not distribute RPM's or pre-built binaries; contact your vendor if you can't build from source. If you want to build from source, please see the README as a starting point. __ OpenSSL Project