Do I need to take action on a 10.04 LTS server to avoid the heartbleed vulnerability?

8,540

Solution 1

The version in 10.04 is too old to have the vulnerability, no action is needed over the heart bleed bug.

Solution 2

you can check if your server is affected:

http://filippo.io/Heartbleed/#«yourserver.tld»

Share:
8,540

Related videos on Youtube

FvD
Author by

FvD

Updated on September 18, 2022

Comments

  • FvD
    FvD over 1 year

    From the heartbleed.com website, I see that OpenSSL 0.9.8 is NOT vulnerable, which is the version that is available on 10.04. That should mean that actually having stuck with 10.04 until now has avoided any problems with this issue for my production servers.

    Is that correct or am I still missing something and there is action that should be taken on 10.04 servers?

  • snez
    snez about 10 years
    OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable
  • Thomas Weller
    Thomas Weller about 10 years
    If you don't exactly know your Ubuntu version and the obvious command uname -a is not helpful, try lsb_release -d -s.
  • belacqua
    belacqua about 10 years
    This assumes that the server is currently publicly accessible....
  • belacqua
    belacqua about 10 years
    +1 If you have 0.9.8 you are fine ; 10.04 is OK unless you've done something interesting. Use openssl version to check.