* Stefan Botter <[email protected]> [2014-04-15 08:38]: > If you are uncomfortable with still running on the vulnerable PMBS, I > can shut it down until the update is finished.
It is currently being actively exploited and Packamn is a visible and valuable target, so IMO something needs to be done ASAP. Instead of shutting it down, how about just rebuilding the OpenSSL package from 12.2 with -DOPENSSL_NO_HEARTBEATS and using that for the time being? -- Guido Berhoerster _______________________________________________ Packman mailing list [email protected] http://lists.links2linux.de/cgi-bin/mailman/listinfo/packman
