Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Heartbleed bug - does it affect pfs 2.1?

    Scheduled Pinned Locked Moved OpenVPN
    7 Posts 4 Posters 4.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dmad
      last edited by

      I did a look around the interface and I don't see any references to package versions or anything like that.. i'm sure this would have come up if it was but I might as well ask.

      http://heartbleed.com/

      OpenVPN uses openSSL as far as I know, so.. affected or not?

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        Yes. An update is coming soon.

        1 Reply Last reply Reply Quote 0
        • D
          dmad
          last edited by

          @cmb:

          Yes. An update is coming soon.

          In the form of a firmware update or..? what version will be the patched version?

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            update here. https://forum.pfsense.org/index.php?topic=74796.msg408899#msg408899

            1 Reply Last reply Reply Quote 0
            • S
              sheepthief
              last edited by

              Just a reference for anyone searching the forums, the official reference for the bug is CVE-2014-0160

              1 Reply Last reply Reply Quote 0
              • N
                ncolunga
                last edited by

                If pfsense 2.1 uses openssl-1.0.0_10 it shouldn't be affected by this bug. Isn't it?

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by

                  @ncolunga:

                  If pfsense 2.1 uses openssl-1.0.0_10 it shouldn't be affected by this bug. Isn't it?

                  2.1 and 2.1.1 have vulnerable openssl versions.
                  https://pfsense.org/security/advisories/pfSense-SA-14_04.openssl.asc

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.