Heartbleed

70 views
Skip to first unread message

Pieter J. van Horssen

unread,
Apr 12, 2014, 6:06:59 AM4/12/14
to joomla-...@googlegroups.com
The last couple of weeks there is a lot of noise about the OpenSSL bug Heartbleed.
I was just thinking whether we have this problem in Joomla and if so, what can we do about it?

Hannes Papenberg

unread,
Apr 12, 2014, 6:43:23 AM4/12/14
to joomla-...@googlegroups.com
No, there is nothing that Joomla can or has to do about this. Heartbleed
is in OpenSSL, which Joomla does not reference anywhere. It is a problem
in the server, not in Joomla that runs ON the server.

Cliff Ford

unread,
Apr 12, 2014, 7:03:39 AM4/12/14
to joomla-...@googlegroups.com
If you go to your Site System Information and look for OpenSSL you may
find which version it is using (if it is using it at all). The sites I
look after were using older non-vulnerable versions. You can look it all
up here: http://heartbleed.com/ In short, OpenSSL versions 1.0.1 through
1.0.1f are vulnerable and other versions are not. If your site is
vulnerable - contact your service provider.

Cliff
Reply all
Reply to author
Forward
0 new messages