GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » Openssl problem
Openssl problem [message #112294] Tue, 08 April 2014 11:12 Go to next message
urban.hake is currently offline  urban.hake
Messages: 18
Registered: May 2012
Location: Sweden
What is being done about this?

problem Description
The vulnerability in OpenSSL 1.0.1 (and 1.0.2-beta) can be used to read the private memory of the application protected with OpenSSL
and thus get hold of such keys from X.509 certificates, username and password.

solution
Upgrade to OpenSSL version 1.0.1g
Re: Openssl problem [message #112296 is a reply to message #112294] Tue, 08 April 2014 11:23 Go to previous messageGo to next message
urban.hake is currently offline  urban.hake
Messages: 18
Registered: May 2012
Location: Sweden
more to read....

http://www.openssl.org/news/index.html
Re: Openssl problem [message #112313 is a reply to message #112296] Tue, 08 April 2014 13:10 Go to previous messageGo to next message
Pavel Dobry (Kerio) is currently offline  Pavel Dobry (Kerio)
Messages: 2057
Registered: October 2003
Location: Czech Republic
Already discussed here: http://forums.kerio.com/t/27033//

Re: Openssl problem [message #112316 is a reply to message #112313] Tue, 08 April 2014 13:46 Go to previous messageGo to next message
vlada is currently offline  vlada
Messages: 7
Registered: May 2005
Pavel Dobry (Kerio) wrote on Tue, 08 April 2014 13:10
Already discussed ...


Sorry, there is no discussion, only a tensioned expectation.
Re: Openssl problem [message #112321 is a reply to message #112316] Tue, 08 April 2014 14:41 Go to previous messageGo to next message
Neil Whiteside (Kerio) is currently offline  Neil Whiteside (Kerio)
Messages: 318
Registered: September 2013
Location: UK

All updates will be posted at http://forums.kerio.com/t/27043//

We are working on a hotfix and it should be available in 24 hours. We are trying to speed up the whole release process and necessary testing to the maximum. Thank you for understanding.


Knowledge Base: http://kb.kerio.com/.
Looking for technical support? http://www.kerio.com/support
Re: Openssl problem [message #112323 is a reply to message #112294] Tue, 08 April 2014 14:54 Go to previous messageGo to next message
hugge is currently offline  hugge
Messages: 2
Registered: April 2014
Location: Sweden
The exploit works great on our Kerio-installations. You can read emails, get session id´s and more or less dump everything the server handles. Huge problem. Please get a update *very* soon.

Why have openssl bundled instead of using the system openssl? Then this problem would have been solved 2hours after it got discovered.
Re: Openssl problem [message #112324 is a reply to message #112323] Tue, 08 April 2014 15:09 Go to previous messageGo to next message
Maerad is currently offline  Maerad
Messages: 275
Registered: August 2013
Quote:
Why have openssl bundled instead of using the system openssl? Then this problem would have been solved 2hours after it got discovered.


Just think about for more then 2 seconds Smile

Kerio is made to run on many multiple systems. There are many different programs for SSL to be used, many different versions, many different configs. This way kerio can't work, because they don't know how the system might be configured or maybe some depencies are missing.

Also it wouldn't work with the "easy install" option, because you would have to install, config and link your local openssl installation. Not to mention, that most of the linked assistant systems in the menu might not work, because of a different config, paths and so on.

And don't let me get started in admins with less knowledge, that don't even know HOW to update something or edit a config in bash. Or how to use a specific openssl program version and not the newest for ubuntu.

If you want to provide a full working, configured and easy to install/use system, you are forced to include all important programs it needs. Simple as that.

Same goes for other projects that install each an own tomcat server and java version instead of using the system wide one.
Re: Openssl problem [message #112406 is a reply to message #112324] Wed, 09 April 2014 12:27 Go to previous message
Neil Whiteside (Kerio) is currently offline  Neil Whiteside (Kerio)
Messages: 318
Registered: September 2013
Location: UK

The Hotfixes for Kerio Connect are available here:

http://goo.gl/filNif


Knowledge Base: http://kb.kerio.com/.
Looking for technical support? http://www.kerio.com/support

[Updated on: Wed, 09 April 2014 13:31] by Moderator

Report message to a moderator

Previous Topic: Sophos AV not restarting after def. update
Next Topic: [IMPORTANT] OpenSSL-Bug > Reset PW + Cert after Install
Goto Forum:
  


Current Time: Tue May 30 00:17:34 CEST 2023

Total time taken to generate the page: 0.05505 seconds