* Stefan Botter <[email protected]> [2014-04-15 08:38]:
> If you are uncomfortable with still running on the vulnerable PMBS, I
> can shut it down until the update is finished.

It is currently being actively exploited and Packamn is a visible
and valuable target, so IMO something needs to be done ASAP.
Instead of shutting it down, how about just rebuilding the OpenSSL
package from 12.2 with -DOPENSSL_NO_HEARTBEATS and using that for
the time being?
-- 
Guido Berhoerster

_______________________________________________
Packman mailing list
[email protected]
http://lists.links2linux.de/cgi-bin/mailman/listinfo/packman

Antwort per Email an