Announcing ngx_pagespeed security release 1.9.32.11

49 views
Skip to first unread message

Jeffrey Crowell

unread,
Dec 10, 2015, 1:30:01 PM12/10/15
to ngx-pagespe...@googlegroups.com

Release 1.9.32.11-beta security release.


Release 1.9.32.11 fixes one security issue. It is otherwise identical to the previous release (1.9.32.10). We recommend that all users upgrade to receive these fixes.


In versions between 1.8.31.2 and 1.9.32.10, PageSpeed was built with a version of OpenSSL that was vulnerable to the issues detailed in the December 4, 2015 security advisory ( https://www.openssl.org/news/secadv/20151203.txt ). We have updated our crypto library to fix these issues.


We recommend that all users upgrade. If this is not possible, however, the following workaround is available:

  • The OpenSSL vulnerability only applies if you have FetchHttps enabled and have configured PageSpeed to fetch HTTPS content over the open internet.  Disabling FetchHttps will prevent these crashes, but will also disable PageSpeed's optimizations for any content that must be fetched over HTTPS.

Issues Resolved since 1.9.32.10


Installation Instructions

To install this update, see: https://developers.google.com/speed/pagespeed/module/build_ngx_pagespeed_from_source

The installation process remains the same, even if you've already installed a previous version.


Jeff Crowell

PageSpeed Team

Google

Centmin Mod George

unread,
Dec 11, 2015, 3:23:02 AM12/11/15
to ngx-pagespeed-discuss, ngx-pagespe...@googlegroups.com
Thanks Jeff for the heads up and also Centmin Mod git pull request notification :)

Has PageSpeed team looked at using LibreSSL instead of OpenSSL ?

cheers

George

Jeffrey Crowell

unread,
Dec 11, 2015, 10:02:52 AM12/11/15
to ngx-pagespeed-discuss, ngx-pagespe...@googlegroups.com
George,

We currently use BoringSSL instead of OpenSSL. We probably *could* build against LibreSSL, but as Chromium also uses BoringSSL it's easier to keep in sync there. BoringSSL has avoided a few bugs in OpenSSL, and LibreSSL has avoided a few others. 

Thanks,

Jeff

--
You received this message because you are subscribed to the Google Groups "ngx-pagespeed-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ngx-pagespeed-di...@googlegroups.com.
Visit this group at http://groups.google.com/group/ngx-pagespeed-discuss.
For more options, visit https://groups.google.com/d/optout.

Centmin Mod George

unread,
Dec 11, 2015, 1:05:43 PM12/11/15
to ngx-pagespeed-discuss, ngx-pagespe...@googlegroups.com
Ah makes total sense :)

John Mase

unread,
Dec 12, 2015, 2:30:42 PM12/12/15
to ngx-pagespeed-discuss, ngx-pagespe...@googlegroups.com
i see 1.10.33.0
is this the latest version ?

Otto van der Schaaf

unread,
Dec 12, 2015, 5:32:19 PM12/12/15
to ngx-pagespeed-discuss, ngx-pagespe...@googlegroups.com


On Saturday, December 12, 2015 at 8:30:42 PM UTC+1, John Mase wrote:
i see 1.10.33.0
is this the latest version ?

1.10.33.0 hasn't been announced, that branch is a work in progress. 
Reply all
Reply to author
Forward
0 new messages