|
#1
|
|||
|
|||
|
In light of this new OpenSSL issue:
http://it.slashdot.org/story/14/06/0...ts-all-clients Do we have OpenSSL in CSSU? Do we want to pull in all the fixes for OpenSSL for issues like this? Also, it would be good to have a security examination of the N900 and identify all the packages that are important for security (so that we can keep them maintained in CSSU or if they are closed, look at how to replace them with something open) |
| The Following 10 Users Say Thank You to jonwil For This Useful Post: | ||
|
#2
|
|||
|
|||
|
http://www.symantec.com/connect/blog...ter-heartbleed
It seems we avoided heartbleed issues by being on 0.9.8n, however, latest CVE's recommend updating 0.9.8 to 0.9.8za I believe some of your question where discussed on the heartbleed thread http://talk.maemo.org/showthread.php?t=92998
__________________
The stable-beast currently runs... 21.2011.38-1Smaemo8 (CSSU Stable) 2.6.28.10power53 (125-600Mhz SR VDD1&2) Wiki Admin sixwheeledbeast's wiki Testing Squad Subscriber - mcallerx - tenminutecore - FlopSwap - Qnotted - zzztop - Bander - Fight2048 - Before posting or starting a thread please try this. |
| The Following 4 Users Say Thank You to sixwheeledbeast For This Useful Post: | ||
|
#3
|
|||
|
|||
|
Sounds like someone should compile and release 0.9.8za for the n900 at least. Is that part of CSSU, or just generally available in the repos as a separate package?
|
| The Following User Says Thank You to shawnjefferson For This Useful Post: | ||
|
#4
|
|||
|
|||
|
__________________
The stable-beast currently runs... 21.2011.38-1Smaemo8 (CSSU Stable) 2.6.28.10power53 (125-600Mhz SR VDD1&2) Wiki Admin sixwheeledbeast's wiki Testing Squad Subscriber - mcallerx - tenminutecore - FlopSwap - Qnotted - zzztop - Bander - Fight2048 - Before posting or starting a thread please try this. |
| The Following 2 Users Say Thank You to sixwheeledbeast For This Useful Post: | ||
|
#5
|
|||
|
|||
|
Seems like it's in the SSU repository (among others too). On my device, it's thumb compiled by fmg, so hopefully he will compile the newest one. I guess it will have to pass through CSSU-dev first though... I'm not really up on how CSSU stuff works and it seems like a very small group of people own it.
|
|
#6
|
|||
|
|||
|
Quote:
More a small dedicated group of devs contribute to it as a team.
__________________
The stable-beast currently runs... 21.2011.38-1Smaemo8 (CSSU Stable) 2.6.28.10power53 (125-600Mhz SR VDD1&2) Wiki Admin sixwheeledbeast's wiki Testing Squad Subscriber - mcallerx - tenminutecore - FlopSwap - Qnotted - zzztop - Bander - Fight2048 - Before posting or starting a thread please try this. |
| The Following 5 Users Say Thank You to sixwheeledbeast For This Useful Post: | ||
|
#7
|
|||
|
|||
|
Community is not just ask and receive.
Everyone can contribute, maybe with small things, but the concept of community starts from this. No one owns, everyone contributes to make it better |
| The Following 3 Users Say Thank You to xes For This Useful Post: | ||
|
#8
|
|||
|
|||
|
Quote:
Point me to the patch that fixes that CVE and I'll see what I can do EDIT: "Pointing" is raising a bug on BMO, place a link to bug here
__________________
Never fear. I is here. 720p video support on N900,SmartReflex on N900,Keyboard and mouse support on N900 Nothing is impossible - Stable thumb2 on n900 Community SSU developer kernel-power developer and maintainer |
| The Following 6 Users Say Thank You to freemangordon For This Useful Post: | ||
|
#9
|
|||
|
|||
|
@fremangordon
maybe that rebase on 0.9.8za and apply nokia/maemo patches to that would require almost the same time. For sure latest CVE 2014-0224 is really a pain for every mobile device using a vpn. ref: http://www.openssl.org/news/secadv_20140605.txt So also CVE 2014 0195/221/3470 affect the N900's openssl current version. After this, we should expect many openssl updates in the next months since actually there is a massive bug hunting.. Last edited by xes; 2014-06-07 at 12:35. |
| The Following 3 Users Say Thank You to xes For This Useful Post: | ||
|
#10
|
|||
|
|||
|
Quote:
So, if someone finds the relevant patches/commits, I'll backport them in CSSU
__________________
Never fear. I is here. 720p video support on N900,SmartReflex on N900,Keyboard and mouse support on N900 Nothing is impossible - Stable thumb2 on n900 Community SSU developer kernel-power developer and maintainer |
| The Following 6 Users Say Thank You to freemangordon For This Useful Post: | ||
![]() |
| Tags |
| maemo 5, sarcasm |
|
|