Live GIS Disc Press Release 49

From OSGeo
Revision as of 05:34, 13 April 2014 by Wiki-Camerons (talk | contribs) (Created page with "= OSGeo-Live and Heartbleed vulnerability= 14 April 2014 The [http://heartbleed.com/ Heartbleed Bug], which is a vulnerability in OpenSSL is also applicable for a number of the...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

OSGeo-Live and Heartbleed vulnerability

14 April 2014

The Heartbleed Bug, which is a vulnerability in OpenSSL is also applicable for a number of the OSGeo live releases. OSGeo-Live is designed for demonstrating OSGeo software rather than being used for setting up hardened production servers, and as such shouldn't be used as a base system for storing sensitive data.

Even so, we do recommend anyone who has installed OSGeo-Live should patch the system.

OSGeo-Live releases effected include

OSGeo-Live releases based on Ubuntu 12.04 are effected. This includes versions:

  • 6.0
  • 6.5
  • 7.0
  • 7.9

How to Fix

The following commands run from the command line will address the patch:

 sudo apt-get install libssl1.0.0