{"id":2062,"date":"2014-06-09T15:59:03","date_gmt":"2014-06-09T19:59:03","guid":{"rendered":"http:\/\/blog.litespeedtech.com\/?p=2062"},"modified":"2014-06-09T15:59:03","modified_gmt":"2014-06-09T19:59:03","slug":"lsws-4-2-12-fixes-newest-openssl-vulnerability","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2014\/06\/09\/lsws-4-2-12-fixes-newest-openssl-vulnerability\/","title":{"rendered":"LSWS 4.2.12 Fixes Newest OpenSSL Vulnerability"},"content":{"rendered":"<p>This latest OpenSSL vulnerability affects all versions of OpenSSL, so it is suggested that all users upgrade to 4.2.12.<!--more--><\/p>\n<h3>A New OpenSSL Vulnerability<\/h3>\n<p>Well, at least we all know how to upgrade OpenSSL now.<\/p>\n<p>Right on the heels of <a title=\"LiteSpeed Security Patch to Fix Heartbleed Bug in OpenSSL\" href=\"http:\/\/blog.litespeedtech.com\/2014\/04\/08\/litespeed-security-patch-to-fix-heartbleed-bug-in-openssl\/\">Heartbleed<\/a>, Japanese researcher Masashi Kikuchi has recently discovered and reported the\u00a0CCS Injection<span style=\"color: #252525;\">\u00a0vulnerability (CVE-2014-0224). There is some disagreement over whether this bug is more or <a title=\"Google's Adam Langley discusses the new vulnerability\" href=\"https:\/\/www.imperialviolet.org\/2014\/06\/05\/earlyccs.html\">less dangerous<\/a> than Heartbleed, though most seem to think it is less likely to be exploited.<\/span><\/p>\n<p>Here is <a title=\"Kikuchi's explanation of CCS Injection vulnerability\" href=\"http:\/\/ccsinjection.lepidum.co.jp\/blog\/2014-06-05\/CCS-Injection-en\/index.html\">Kikuchi&#8217;s explanation of the bug<\/a>.<\/p>\n<h3>Fixed in 4.2.12<\/h3>\n<p>We have released our newest version of LiteSpeed Web Server with a fix for this bug. <strong>The easiest way to upgrade is using the lsup script:<\/strong><br \/>\n<code>\/usr\/local\/lsws\/admin\/misc\/lsup.sh -f -v 4.2.12<\/code><\/p>\n<h3>Affected Versions<\/h3>\n<p>Unlike Heartbleed, which\u00a0had been introduced to the OpenSSL code relatively recently, this vulnerability exists in all (or all recent) versions of OpenSSL. This means that <strong>we recommend all users to upgrade to 4.2.12 when they have a chance<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This latest OpenSSL vulnerability affects all versions of OpenSSL, so it is suggested that all users upgrade to 4.2.12.<\/p>\n","protected":false},"author":1,"featured_media":2542,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[27,23],"tags":[],"class_list":["post-2062","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-server","category-security"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2014\/08\/brokenchain-hi.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/2062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=2062"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/2062\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/2542"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=2062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=2062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=2062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}