[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: OpenSSL Heartbleed bug, Apache still vulnerable?



Sven Hartge:
> Jochen Spieker <ml@well-adjusted.de> wrote:
> 
>> Yes, here it is:
>> https://code.google.com/p/mod-spdy/issues/detail?id=85
> 
>>| Note that just disabling the spdy module in Apache won't work, because
>>| the SSL library itself is replaced. Easiest fix on Debian is to remove
>>| the mod-spdy package from the system (for now).
> 
>> Thanks for helping me to find this. After removing mod-spdy-beta
>> and stopping and starting Apache, the test tools deem my system safe.
> 
> Ürx, nasty one. 
> 
> I presume mod_spdy is not from any offical package (cannot find any
> package matching "spdy" in Debian anywhere) but a module compiled by
> yourself?

I think I installed a .deb from Google which added the file
/etc/apt/sources.list.d/mod-spdy.list:

deb http://dl.google.com/linux/mod-spdy/deb/ stable main

As you wrote elsewhere, a patch is available and updated binaries should
be available soon:

https://code.google.com/p/mod-spdy/issues/detail?id=85#c2

J.
-- 
Ultimately, the Millenium Dome is a spectacular monument of the
doublethink of our times.
[Agree]   [Disagree]
                 <http://www.slowlydownward.com/NODATA/data_enter2.html>

Attachment: signature.asc
Description: Digital signature


Reply to: