HeartBleed In RHEL

Home » CentOS » HeartBleed In RHEL
CentOS 3 Comments

I know I’m slightly OT here, asking about RHEL, but since CentOS is now a part of RH, I’m hoping I won’t be summarily ejected.

I’ve seen several articles that listed CentOS 6.x as vulnerable, but DID NOT LIST RHEL 6.

I’d think that if CentOS 6.x is vulnerable, then so would RHEL 6.x, since CentOS is made from RHEL sources.

Does anyone know for sure either way?

thanks!

3 thoughts on - HeartBleed In RHEL

  • see https://access.redhat.com/security/cve/CVE-2014-0160
    This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6.4 and earlier, Red Hat JBoss Enterprise Application Platform 5 and 6, and Red Hat JBoss Web Server 1 and 2. This issue does affect Red Hat Enterprise Linux
    6.5, Red Hat Enterprise Virtualization Hypervisor 6.5, and Red Hat Storage 2.1, which provided openssl 1.0.1e. Errata have been released to correct this issue.