Heartbleed and the Debian Way

With all the news about the Heartbleed vulnerability in the OpenSSL package lately I figured that I should make sure my servers were patched. In looking at the version I have installed it seemed I was indeed running one of the affected versions.

$ openssl version
OpenSSL 1.0.1 14 Mar 2012

I was concerned and confused because I was sure that I had made all the recent security updates which I did confirm with:

# apt-get dist-upgrade
Reading package lists… Done
Building dependency tree
Reading state information… Done
Calculating upgrade… Done
0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.

So I needed to understand how I could be running all the latest updates but still have version of a package that was in the range of known impacted versions. This led me to some “apt” tools I was not previously aware of.

# apt-get changelog openssl
openssl (1.0.1-4ubuntu5.12) precise-security; urgency=medium

* SECURITY UPDATE: side-channel attack on Montgomery ladder implementation
– debian/patches/CVE-2014-0076.patch: add and use constant time swap in
crypto/bn/bn.h, crypto/bn/bn_lib.c, crypto/ec/ec2_mult.c,
util/libeay.num.
– CVE-2014-0076
* SECURITY UPDATE: memory disclosure in TLS heartbeat extension
– debian/patches/CVE-2014-0160.patch: use correct lengths in
ssl/d1_both.c, ssl/t1_lib.c.
– CVE-2014-0160

— Marc Deslauriers Mon, 07 Apr 2014 15:45:14 -0400

You can see above in the output of “apt-get changelog openssl”, the comment in bold shows that OpenSSL on my system has indeed been patched. I always love it when I learn something new and useful about how the Debian system works.

Week 15 2014

RSP

Tour of the Battenkill

Week 14 2014

Week 13 2014

Week 12 2014

Week 11 2014

This is from the trip Theo and I took to Agoura Hills CA. as training for the upcoming bike season.

The group at Malibu Beach

Our bikes in the hills.

Papaw

This is my Grandad, he is turning 93 in a few weeks. He just had carotid endarterectomy 12 hours before this picture and here he is anxiously awaiting discharge. He looks forward to every new day.

Happy Birthday to the WWW

The WWW turns 25. Thank you TimBL. It was created on this:

Foggy morning ride.

20140111_100610_LLS
Then we got muddy.
11894842076_8a8ca4ed3f_b

Framectomy

I went over to Theo’s for some garage therapy. We worked on stripping the frame of his 900SS Ducati for repairs. He has taken the bike from…

to this,

and this,

and this,

all so he could fix this.

I suggested this instead,

but he insisted on a more “upscale” repair ;-).