The Apache Haus Forum

Forum Topics => Announcements => Topic started by: Gregg on March 04, 2016, 08:05:17 PM

Title: OpenSSL 1.0.2g & 1.0.1s updates available
Post by: Gregg on March 04, 2016, 08:05:17 PM
Apache 2.2.31 & 2.4.18 downloads have been updated to OpenSSL 1.0.2g
Separate update packages available with only the needed files to upgrade previous 2.2.31 & 2.4.18 also available.

This is a security update (DROWN vulnerability). Users of OpenSSL 1.0.2 prior to 1.0.2g and OpenSSL 1.0.1 prior to 1.0.1s are encouraged to upgrade.

These packages can be found on our download page (http://www.apachehaus.com/cgi-bin/download.plx).

The OpenSSL change log for 1.0.2g can be found here (https://www.openssl.org/news/cl102.txt).
The OpenSSL change log for 1.0.1s can be found here (https://www.openssl.org/news/cl101.txt).

Note: There are no OpenSSL 0.9.8 downgrade packages available as OpenSSL 0.9.8 and 1.0.0 have reached End of Life.