OpenSSL 1.0 and 1.1 have both received security updates: https://mta.openssl.org/pipermail/openssl-announce/2017-January/000094.html
I built the updated packages successfully but I don't have time to test them. Please test these and push on my behalf. Please verify the signatures and hashes of the source code, and read over the patches to make sure they are correct. Leo Famulari (2): gnu: openssl: Replace with openssl-1.0.2k [security fixes]. gnu: openssl-next: Update to 1.1.0d [fixes CVE-2017-{3730,3731,3732}]. gnu/packages/tls.scm | 25 +++++++++++++++++++++++-- 1 file changed, 23 insertions(+), 2 deletions(-) -- 2.11.0