Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade open SSL to 1.1.1n #5161

Closed
Forge36 opened this issue Mar 21, 2022 · 6 comments
Closed

Upgrade open SSL to 1.1.1n #5161

Forge36 opened this issue Mar 21, 2022 · 6 comments

Comments

@Forge36
Copy link

Forge36 commented Mar 21, 2022

There is one security issues in OpenSSL 1.1.1

Major changes between OpenSSL 1.1.1m and OpenSSL 1.1.1n [15 Mar 2022]
Fixed a bug in the BN_mod_sqrt() function that can cause it to loop forever for non-prime moduli (CVE-2022-0778)

https://www.openssl.org/news/openssl-1.1.1-notes.html

#4820 is updating to 1.1.1l

@hgy59
Copy link
Contributor

hgy59 commented Mar 22, 2022

update is now merged into master.
Packages depending on cross/openssl:

  • ffmpeg
  • aria2
  • bazarr
  • beets
  • borgbackup
  • boxbackup-client
  • deluge
  • domoticz
  • duplicity
  • ejabberd
  • erlang
  • ffsync
  • flexget
  • fossil-scm
  • git
  • haproxy
  • homeassistant
  • icecast
  • irssi
  • itools
  • jackett
  • kiwix
  • memcached
  • mercurial
  • monit
  • mosh
  • mosquitto
  • mtproxy
  • mutt
  • ntopng
  • nzbdrone
  • octoprint
  • prowlarr
  • python
  • python2
  • python3
  • python310
  • python38
  • rdiff-backup
  • ruby
  • rutorrent
  • sabnzbd
  • salt-master
  • salt-minion
  • shairport-sync
  • sickchill
  • sonarr
  • squidguard
  • stunnel
  • synocli-disk
  • synocli-file
  • synocli-monitor
  • synocli-net
  • transmission
  • tvheadend
  • vim
  • znc

@hgy59 hgy59 mentioned this issue Mar 22, 2022
45 tasks
@hgy59 hgy59 pinned this issue Mar 22, 2022
@BenjV
Copy link

BenjV commented Mar 22, 2022

Maybe a good moment to switch to OpenSSL 3.0.2 for recent packages like python 3.10
The 1.1.1 version is in maintenance mode and the support will stop next year.

See:
https://www.ssltrust.com.au/blog/openssl-3-what-to-know#:~:text=In%20fact%2C%20OpenSSL%201.1.,and%20is%20NOT%20backwards%20compatible.

EDIT:
Forget this, even python is not yet ready to be used with OpenSSL 3.0

@hgy59 hgy59 mentioned this issue Apr 2, 2022
10 tasks
@hgy59
Copy link
Contributor

hgy59 commented Jun 10, 2022

@Forge36 we already update openssl to v1.1.1o in #5266.
All packages released after May 12, 2022 are built with v1.1.1o.

@Forge36
Copy link
Author

Forge36 commented Jun 10, 2022

Thanks! Should this be closed or updated in some way?

@hgy59
Copy link
Contributor

hgy59 commented Jun 25, 2022

closing this, as openssl is already updated to 1.1.1o with #5266 and #5324 will update to openssl v1.1.1p.

@hgy59 hgy59 closed this as completed Jun 25, 2022
@hgy59 hgy59 unpinned this issue Jun 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants