OpenSSL 1.0.2 < 1.0.2k Multiple Vulnerabilities

Problems with the Windows version of XAMPP, questions, comments, and anything related.

OpenSSL 1.0.2 < 1.0.2k Multiple Vulnerabilities

Postby Mishiago » 11. February 2017 10:32

Hi everyone.

I Just found that OpenSSL 1.0.2j has Multiple Vulnerabilities and should be updated to 1.0.2k version.

For more details go to: https://www.openssl.org/news/secadv/20170126.txt

Please Advise.

Mishiago.
Mishiago
 
Posts: 2
Joined: 11. February 2017 10:27
XAMPP version: 5.6.30
Operating System: Windows Server 2012 R2

Re: OpenSSL 1.0.2 < 1.0.2k Multiple Vulnerabilities

Postby Altrea » 11. February 2017 12:31

Which of this vulnerabilities is critical for a local test and development environment?
We don't provide any support via personal channels like PM, email, Skype, TeamViewer!

It's like porn for programmers 8)
User avatar
Altrea
AF Moderator
 
Posts: 8969
Joined: 17. August 2009 13:05
XAMPP version: several
Operating System: Windows 10 Pro x64

Re: OpenSSL 1.0.2 < 1.0.2k Multiple Vulnerabilities

Postby Mishiago » 16. February 2017 14:44

What difference does it make?!?! It doesn't matter, there is known Vulnerability and you decided to ask rhetorical questionץץ
Mishiago
 
Posts: 2
Joined: 11. February 2017 10:27
XAMPP version: 5.6.30
Operating System: Windows Server 2012 R2

Re: OpenSSL 1.0.2 < 1.0.2k Multiple Vulnerabilities

Postby Nobbie » 16. February 2017 18:15

Mishiago wrote: Just found that OpenSSL 1.0.2j has Multiple Vulnerabilities and should be updated to 1.0.2k version.


Why should it be updated? What does a vulnerability, when the server is not exposed? That costs only manpower for nothing - do you want to join Bitnami and fix these vulneratbilities?
Nobbie
 
Posts: 9814
Joined: 09. March 2008 13:04

Re: OpenSSL 1.0.2 < 1.0.2k Multiple Vulnerabilities

Postby Altrea » 16. February 2017 21:15

Mishiago wrote:What difference does it make?!?!

A huge difference. Don't fix something that is not broken.
There is no benefit from it. Instead you could create issues with that upgrade which really matters.

Create your own webserver stack and release it for free than you can choose yourself if you want to update it daily.
XAMPP will not do that.
We don't provide any support via personal channels like PM, email, Skype, TeamViewer!

It's like porn for programmers 8)
User avatar
Altrea
AF Moderator
 
Posts: 8969
Joined: 17. August 2009 13:05
XAMPP version: several
Operating System: Windows 10 Pro x64


Return to XAMPP for Windows

Who is online

Users browsing this forum: No registered users and 53 guests