CVE-2014-0160 / heartbleed openssl bug & mod_spdy

258 views
Skip to first unread message

JT Olds

unread,
Apr 8, 2014, 1:50:42 AM4/8/14
to mod-spdy...@googlegroups.com
In trying to fix the most recent openssl vulnerability on my Apache servers, installing the latest Apache and openssl was not enough to fix the vulnerability.

Since mod-spdy is built against openssl, it was keeping the vulnerability alive until I disabled it.

mod-spdy packages need to be rebuilt, or uninstalled.

You can check if your system is vulnerable with a tool like https://github.com/titanous/heartbleeder/

Tarun Reddy

unread,
Apr 8, 2014, 9:06:42 AM4/8/14
to mod-spdy...@googlegroups.com
I guess we'll finally find out if this project is dead or not. No updates on Spdy 3.1 were one thing, but this effectively kills the project if we don't have a fix. I'm uninstalling now.

Eric Reiche

unread,
Apr 8, 2014, 9:47:13 AM4/8/14
to mod-spdy...@googlegroups.com
Yes, it took me a while to realize that it was mod_spdy causing this problem. Uninstalled it, too.

Matthew Steele

unread,
Apr 8, 2014, 10:17:45 AM4/8/14
to mod-spdy...@googlegroups.com
Hi all,

Thanks for the report.  I am working on updating mod_spdy's openssl version and getting a new release out ASAP.


--
You received this message because you are subscribed to the Google Groups "mod-spdy-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to mod-spdy-discu...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Mike Lawson

unread,
Apr 9, 2014, 12:12:42 PM4/9/14
to mod-spdy...@googlegroups.com
Looks like yesterday's update (v0.9.4.2) has added ECDHE and support for Forward Security.    Thumbs up for that!
Reply all
Reply to author
Forward
0 new messages