Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    More OpenSSL vulnerabilities

    Scheduled Pinned Locked Moved General pfSense Questions
    19 Posts 12 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hootenanny
      last edited by

      @jimp:

      There will be a 2.1.4 coming, but we're not rushing it out like we did with Heartbleed. ETA mid next-week.

      Hi jimp,

      I run an OpenVPN client from my pfsense box. In the meantime is it possible to update OpenSSL to 0.9.8za without adversely affecting the base system?

      Cheers,

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Previous advice immediately after Heartbleed broke was not to do that, there's a good chance you'll break something.
        @cmb:

        Don't try to patch or upgrade OpenSSL, you'll more than likely just break things. Each PBI has its own copy, plus the base system.

        Steve

        1 Reply Last reply Reply Quote 0
        • R
          Reiner030
          last edited by

          @jimp:

          It's not Heartbleed by a long shot.

          There will be a 2.1.4 coming, but we're not rushing it out like we did with Heartbleed. ETA mid next-week.

          It seems that OpenSSL in 2.0.x is also vulnerable to this bug. Is there then also a 2.0.4 security update available?

          Bests

          1 Reply Last reply Reply Quote 0
          • K
            kpa
            last edited by

            @Reiner030:

            @jimp:

            It's not Heartbleed by a long shot.

            There will be a 2.1.4 coming, but we're not rushing it out like we did with Heartbleed. ETA mid next-week.

            It seems that OpenSSL in 2.0.x is also vulnerable to this bug. Is there then also a 2.0.4 security update available?

            Bests

            I wouldn't hold my breath, the 2.0.x versions are marked as "deprecated" on the release information page. There was nothing done on them to fix the heartbleed vulnerability as far as I know.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              No, there will not be a 2.0.x release, that line is no longer supported.

              Don't replace the OpenSSL in base yourself.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                @kpa:

                There was nothing done on them to fix the heartbleed vulnerability as far as I know.

                The 2.0.X versions were not vulnerable to Heartbleed, but they may be vulnerable to whole host of other things.ย  ;)

                Steve

                1 Reply Last reply Reply Quote 0
                • H
                  hootenanny
                  last edited by

                  @jimp:

                  There will be a 2.1.4 coming, but we're not rushing it out like we did with Heartbleed. ETA mid next-week.

                  Any idea when we can expect to see 2.1.4 release?

                  Cheers,

                  1 Reply Last reply Reply Quote 0
                  • H
                    Harvy66
                    last edited by

                    @hootenanny:

                    @jimp:

                    There will be a 2.1.4 coming, but we're not rushing it out like we did with Heartbleed. ETA mid next-week.

                    Any idea when we can expect to see 2.1.4 release?

                    Cheers,

                    "ETA mid next-week."?

                    1 Reply Last reply Reply Quote 0
                    • H
                      hootenanny
                      last edited by

                      @Harvy66:

                      "ETA mid next-week."?

                      Just asking as that was last week, in the meantime I still can't use OpenVPN because of the vuln.

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Hit a couple snags but it's still coming soon.

                        You can use OpenVPN if you use a TLS auth key. Also if you update your clients, it's fine. Please read all of the text I quoted earlier in the thread.

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.