Re: [CentOS] centos 4.6 and openssl

2008-02-02 Thread Johnny Hughes
Paul A wrote: Hi, I was compiling a new version of bind on my centos 4.6 server and I discovered that the openssl version (openssl-0.9.7a-43.17.el4_6.1) has several exploits associated with it. I was wondering aside from removing the RPM and compiling a new version of openssl how can I upgrade

Re: [CentOS] centos 4.6 and openssl

2008-02-01 Thread Ralph Angenendt
Paul A wrote: > I was compiling a new version of bind on my centos 4.6 server and I > discovered that the openssl version (openssl-0.9.7a-43.17.el4_6.1) has > several exploits associated with it. I want proof of that. Ralph pgpLP5398cPzZ.pgp Description: PGP signature __

Re: [CentOS] centos 4.6 and openssl

2008-02-01 Thread Alex White
On Fri, 1 Feb 2008 13:40:32 -0500 "Paul A" <[EMAIL PROTECTED]> took out a #2 pencil and scribbled: > Thanks Alex. > > I'm assuming that if another security exploit is found that the > openssl version number who change on the repo correct, if not how > would yum know to update? > > Thanks, Paul

RE: [CentOS] centos 4.6 and openssl

2008-02-01 Thread Paul A
Behalf Of Alex White P.A > Sent: Friday, February 01, 2008 1:13 PM P.A > To: CentOS mailing list P.A > Subject: Re: [CentOS] centos 4.6 and openssl P.A > P.A > On Fri, 1 Feb 2008 12:49:10 -0500 P.A > "Paul A" <[EMAIL PROTECTED]> took out a #2 pencil and scr

Re: [CentOS] centos 4.6 and openssl

2008-02-01 Thread Alex White
On Fri, 1 Feb 2008 12:49:10 -0500 "Paul A" <[EMAIL PROTECTED]> took out a #2 pencil and scribbled: > Hi, > > I was compiling a new version of bind on my centos 4.6 server and > I discovered that the openssl version > (openssl-0.9.7a-43.17.el4_6.1) has several exploits associated > with it. I was