What the GHOST tells us about free software vulnerability management

Hanno's Blog

Friday, January 30. 2015

What the GHOST tells us about free software vulnerability management


Trackbacks

No Trackbacks

Comments
Display comments as (Linear | Threaded)

It should be noted that RHEL4 is supported up till year 2017. Though I believe there were issues even with fixing shellshock in RHEL4. Other LTS distros have twice shorter support periods.
Also RH backports most of the bugfixes from recent software versions. So php53 in rhel5 has virtually all security fixes up till latest php version. That is what paid support gives.

Ubuntu and even Debian on the other hand are nice sandboxes for kids to play with.
#1 non7top on 2015-01-30 02:11 (Reply)
Oh, thanks for the Info about RHEL4. I have changed the text accordingly.
#1.1 Hanno (Homepage) on 2015-01-30 02:55 (Reply)
"... Red Hat Enterprise ship OpenSSL versions that only support TLS 1.0".

RHEL supports TLS 1.1 and 1.2 in openssl and nss since December 2013 (RHEL 6.5) and also in RHEL 7.0.

https://securityblog.redhat.com/2013/12/11/tlsv1-1-and-tlsv1-2-now-available-in-rhel/
#2 Karsten (Homepage) on 2015-01-30 09:45 (Reply)
Oops, there was a 5 missing in that sentence. Now it's correct :-)
#2.1 Hanno (Homepage) on 2015-01-30 09:51 (Reply)
The Commodore 64 doesn't even have a libc.
#3 ulfh (Homepage) on 2015-01-30 09:59 (Reply)

Add Comment

E-Mail addresses will not be displayed and will only be used for E-Mail notifications.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

 
 

About

This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0.

You can find my web page with links to my work as a journalist here.

I am also publishing a newsletter about climate change and decarbonization technologies.

The blog uses the free software Serendipity and is hosted at schokokeks.org.

Hanno on Mastodon | Contact / Imprint | Privacy / Datenschutz