Forum Discussion

Micha__Iwaszko_'s avatar
Micha__Iwaszko_
Icon for Nimbostratus rankNimbostratus
Nov 17, 2010

OpenSSL vulnerability

http://openssl.org/news/secadv_20101116.txt

 

Does anyone know, whether LTMs are affected?

 

3 Replies

  • All versions of OpenSSL supporting TLS extensions contain this vulnerability

     

    including OpenSSL 0.9.8f through 0.9.8o, 1.0.0, 1.0.0a releases <----------

     

     

    SOL9445: The BIG-IP third party software matrix

     

    https://support.f5.com/kb/en-us/solutions/public/9000/400/sol9445.html?sr=11205917
  • F5 will issue a formal response to these, along with an assessment. If the openssl on-box is vulnerable, it doesn't necessarily mean that the SSL offload capabilities are vulnerable. I'd open a support case and ask them for an assessment on this. Either way, F5 will provide hot fixes, etc. as needed.

     

     

    -Matt
  • F5 will issue a formal response to these, along with an assessment. If the openssl on-box is vulnerable, it doesn't necessarily mean that the SSL offload capabilities are vulnerable. I'd open a support case and ask them for an assessment on this. Either way, F5 will provide hot fixes, etc. as needed.

     

     

    -Matt