Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 17 Jun 2016 06:28:06 +0200
From:      dirk.meyer@dinoex.sub.org (Dirk Meyer)
To:        freebsd-ports@freebsd.org (FreeBSD Ports)
Subject:   Re: openssl-1.0.2.13
Message-ID:  <MIgGZrOFOM@dmeyer.dinoex.sub.org>
References:  <SN2PR20MB084569E9E00B375CE71ABF0F80540@SN2PR20MB0845.namprd20.prod.outlook.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Hallo Gerard Seibert,

> I have a question regarding "openssl-1.0.2.13". Since the port is
> marked as "vulnerable", I was wondering if there is any idea when a
> corrected port will be released?

openssl-1.0.2.13 is the fixed port.

> Also, according to the documentation on
> https://vuxml.FreeBSD.org/freebsd/6f0529e2-2e82-11e6-b2ec-b499baebfeaf.html
> this only affects versions of openssl < 1.0.2_13
> 
> Affected packages
> 		openssl 	< 	1.0.2_13
> 0 	<= 	openssl-devel
> 		libressl 	< 	2.3.6
> 		libressl-devel 	< 	2.4.1
> 
> I am not an expert on this, so perhaps I am misinterpreting this data.

You are correct,
but your system uses an older (cached) version of the vuxml file.

Please update your cache with:
pkg audit -F

kind regards Dirk

- Dirk Meyer, Im Grund 4, 34317 Habichtswald, Germany
- [dirk.meyer@dinoex.sub.org],[dirk.meyer@guug.de],[dinoex@FreeBSD.org]



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?MIgGZrOFOM>