Forum Discussion
Micha__Iwaszko_
Nimbostratus
Nov 17, 2010OpenSSL vulnerability
http://openssl.org/news/secadv_20101116.txt
Does anyone know, whether LTMs are affected?
3 Replies
- nitass
Employee
All versions of OpenSSL supporting TLS extensions contain this vulnerability
including OpenSSL 0.9.8f through 0.9.8o, 1.0.0, 1.0.0a releases <----------
SOL9445: The BIG-IP third party software matrix
https://support.f5.com/kb/en-us/solutions/public/9000/400/sol9445.html?sr=11205917 - L4L7_53191
Nimbostratus
F5 will issue a formal response to these, along with an assessment. If the openssl on-box is vulnerable, it doesn't necessarily mean that the SSL offload capabilities are vulnerable. I'd open a support case and ask them for an assessment on this. Either way, F5 will provide hot fixes, etc. as needed.
-Matt - L4L7_53191
Nimbostratus
F5 will issue a formal response to these, along with an assessment. If the openssl on-box is vulnerable, it doesn't necessarily mean that the SSL offload capabilities are vulnerable. I'd open a support case and ask them for an assessment on this. Either way, F5 will provide hot fixes, etc. as needed.
-Matt
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
