Keep Server Online
If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.
or
A donation makes a contribution towards the costs, the time and effort that's going in this site and building.
Thank You! Steffen
Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
| |
|
Topic: OpenSSL 3.1.3 |
|
Author |
|
dalomi
Joined: 27 Sep 2023 Posts: 1 Location: USA
|
Posted: Wed 27 Sep '23 18:48 Post subject: OpenSSL 3.1.3 |
|
|
Is there a plan to release a new package containing OpenSSL 3.1.3?
Security scanning software is flagging my website as "high" risk due to known vulnerabilities in OpenSSL. |
|
Back to top |
|
admin Site Admin
Joined: 15 Oct 2005 Posts: 692
|
Posted: Wed 27 Sep '23 19:26 Post subject: |
|
|
Yes.
Coming in the next 2.4.58 which is around the corner.
Your scanning software says serverity High.
But the OpenSSL team says:
The OpenSSL project team would like to announce the upcoming release of OpenSSL versions 3.1.3 and 3.0.11.
These releases will be made available on Tuesday 19th September 2023 between 1300-1700 UTC.
These are security-fix releases. The highest severity issue fixed in each of these two releases is Low:
https://www.openssl.org/policies/secpolicy.html
Yours
The OpenSSL Project Team |
|
Back to top |
|
|
|
|
|
|