According to heartbleed.com's FAQ if you don't explicitly specify -DOPENSSL_NO_HEARTBEATS option at compile time, then Heartbeat is enabled for all handshakes. According to tests conducted by various DC software authors, DC clients using OpenSSL as well as ADCH++ are vulnerable.
** Changed in: adchpp Status: New => Confirmed ** Changed in: adchpp Importance: Undecided => Critical ** Also affects: dcplusplus Importance: Undecided Status: New ** Changed in: dcplusplus Importance: Undecided => Critical -- You received this bug notification because you are a member of Dcplusplus-team, which is subscribed to ADCH++. https://bugs.launchpad.net/bugs/1304769 Title: Heartbleed Status in ADCH++: Confirmed Status in DC++: Confirmed Bug description: Seems that ADCH++ is affected, maybe a new release? http://heartbleed.com/ http://filippo.io/Heartbleed/ To manage notifications about this bug go to: https://bugs.launchpad.net/adchpp/+bug/1304769/+subscriptions _______________________________________________ Mailing list: https://launchpad.net/~linuxdcpp-team Post to : linuxdcpp-team@lists.launchpad.net Unsubscribe : https://launchpad.net/~linuxdcpp-team More help : https://help.launchpad.net/ListHelp