Subject: OpenSSL upgrade time?
To: None <current-users@netbsd.org>
From: Michael Graff <explorer@flame.org>
List: current-users
Date: 11/13/2006 14:16:17
The reason I ask is because bind9 9.4 (and later, of course) will be
spamming this at the end of ./configure, on NetBSD-current and older,
with old openssl libraries:
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
WARNING
WARNING
WARNING
WARNING Your OpenSSL crypto library may be vulnerable to
WARNING
WARNING one or more of the the following known security
WARNING
WARNING flaws:
WARNING
WARNING
WARNING
WARNING CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and
WARNING
WARNING CVE-2006-2940.
WARNING
WARNING
WARNING
WARNING It is recommended that you upgrade to OpenSSL
WARNING
WARNING version 0.9.8d/0.9.7l (or greater).
WARNING
WARNING
WARNING
WARNING You can disable this warning by specifying:
WARNING
WARNING
WARNING
WARNING --disable-openssl-version-check
WARNING
WARNING
WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
WARNING