Bug#743889: libssl1.0.0: libssl update does not cause applications that use it to restart

2014-04-08 Thread Thijs Kinkhorst
severity 743889 normal thanks Hi, We have code that checks some of the applications that need to be restarted, but it has a static list of packages to check and it's outdated. We're working on improving that list and providing an other update that will restart those services. I do not

Bug#743889: libssl1.0.0: libssl update does not cause applications that use it to restart

2014-04-07 Thread Jann Horn
Package: libssl1.0.0 Version: 1.0.1e-2+deb7u5 Severity: grave Tags: security Justification: user security hole Dear Maintainer, when I did apt-get updateapt-get upgrade today to get a fix for CVE-2014-0160, I got this from apt: Setting up libssl1.0.0:amd64 (1.0.1e-2+deb7u5) ... Setting up

Bug#743889: [Pkg-openssl-devel] Bug#743889: libssl1.0.0: libssl update does not cause applications that use it to restart

2014-04-07 Thread Kurt Roeckx
On Tue, Apr 08, 2014 at 01:12:34AM +0200, Jann Horn wrote: Package: libssl1.0.0 Version: 1.0.1e-2+deb7u5 Severity: grave Tags: security Justification: user security hole Dear Maintainer, when I did apt-get updateapt-get upgrade today to get a fix for CVE-2014-0160, I got this from apt:

Bug#743889: libssl1.0.0: libssl update does not cause applications that use it to restart

2014-04-07 Thread Steven Chamberlain
Control: found -1 openssl/1.0.1e-2+deb7u4 Hi, A helpful trick I found after upgrade is to: # lsof -nnP | grep libssl.so.1 Look for entries that mention an inode number - this means an unlinked, older version of the library rather than the one currently at that path: nginx 23947root