Menu
No more security fixes for older OpenSSL branches

No more security fixes for older OpenSSL branches

Support for the 0.9.8 and 1.0.0 branches of OpenSSL will end on Dec. 31

The OpenSSL Software Foundation has released new patches for the popular open-source cryptographic library, but for two of its older branches they will likely be the last security updates.

This could spell trouble for some enterprise applications that bundle the 0.9.8 or 1.0.0 versions of OpenSSL and for older systems -- embedded devices in particular -- where updates are rare.

OpenSSL 1.0.0t and 0.9.8zh, which were released Thursday, are expected to be the last updates because support for these these two branches will end on Dec. 31, as listed in the organization's release strategy document.

Both the 1.0.0t and 0.9.8zh versions contain a fix for memory leak vulnerability of moderate severity that can be triggered with malformed X509_ATTRIBUTE structures. Version 0.9.8zh also fixes a low-impact race condition when handling PSK identity hints that has previously been fixed in older 1.0.0, 1.0.1 and 1.0.2 versions.

Versions 1.0.2e and 1.0.1q were also released Thursday, to fix two other moderate vulnerabilities, one that affects only the 1.0.2 branch and one that affects both.

Support for the 1.0.1 branch is expected to end on Dec. 31, 2016 and for the 1.0.2 branch on Dec. 31, 2019. Applications and systems that still rely on OpenSSL 0.9.8 or 1.0.0 should be updated as soon as possible to one of these versions, but this might not be easy.

Previous research has shown that many companies using in-house built software keep poor records of which library versions their developers used in which of their applications. Such companies might have trouble identifying where the soon-to-be-unsupported OpenSSL versions are used in their organizations.

When the critical Heartbleed vulnerability was announced in April 2014, even large software and hardware vendors took months to identify which of their products contained vulnerable versions of OpenSSL.

This makes it very likely that some systems and applications with OpenSSL 0.9.8 and 1.0.0 will never be updated, leaving them exposed to any critical vulnerabilities found in the library in the future.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Featured

Slideshows

Reseller News launches inaugural Hall of Fame lunch

Reseller News launches inaugural Hall of Fame lunch

Reseller News welcomed 2015 and 2016 inductees - Darryl Swann, Dave Rosenberg, Gary Bigwood, Keith Watson, Mike Hill and Scott Green - to the inaugural Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed how the channel can collectively work together to benefit New Zealand, the Kiwi skills shortage and the future of the industry. Photos by Maria Stefina.

Reseller News launches inaugural Hall of Fame lunch
Educating from the epicentre - Why distributors are the pulse checkers of the channel

Educating from the epicentre - Why distributors are the pulse checkers of the channel

​As the channel changes and industry voices deepen, the need for clarity and insight heightens. Market misconceptions talk of an “under pressure” distribution space, with competitors in that fateful “race for relevance” across New Zealand. Amidst the cliched assumptions however, distribution is once again showing its strength, as a force to be listened to, rather than questioned. Traditionally, the role was born out of a need for vendors and resellers to find one another, acting as a bridge between the testing lab and the marketplace. Yet despite new technologies and business approaches shaking the channel to its very core, distributors remain tied to the epicentre - providing the voice of reason amidst a seismic industry shift. In looking across both sides of the vendor and partner fences, the middle concept of the three-tier chain remains centrally placed to understand the metrics of two differing worlds, as the continual pulse checkers of the local channel. This exclusive Reseller News Roundtable, in association with Dicker Data and rhipe, examined the pivotal role of distribution in understanding the health of the channel, educating from the epicentre as the market transforms at a rapid rate.

Educating from the epicentre - Why distributors are the pulse checkers of the channel
Kiwi channel reunites as After Hours kicks off 2017

Kiwi channel reunites as After Hours kicks off 2017

After Hours made a welcome return to the channel social calendar last night, with a bumper crowd of distributors, vendors and resellers descending on The Jefferson in Auckland to kickstart 2017. Photos by Maria Stefina.

Kiwi channel reunites as After Hours kicks off 2017
Show Comments