HeartBleed attack vulnerability (General questions)

by Jan Manek @, (4039 days ago)
edited by Jasmine,

Hello,

we're using wodSSHServer/wodSSHClient components (different versions) in some of our products. I can see that for FIPS complaincy we need to provide for your component also libeay32.dll and ssleay32.dll libraries from OpenSLL.

Are your *SSH* components (and our customers) vulnerable against HeartBleed attack?

Thanks,
Jan Manek

locked

HeartBleed attack vulnerability

by Jasmine, (4039 days ago) @ Jan Manek

Jan,

hi. We use OpenSSL version 0.9.8y so we're not affected by Heartbleed bug.

Hope this helps!
Kreso

locked

HeartBleed attack vulnerability

by Jan Manek @, (4039 days ago) @ Jasmine

Do you mean the latest version of SSH Server?

What about older versions? We're using that component for years and the customers can have installed older versions.

Thanks,
Jan Manek

locked

HeartBleed attack vulnerability

by Jasmine, (4039 days ago) @ Jan Manek

Jan,

older version too, they used older 0.9.8 revisions then.

Kreso

locked

HeartBleed attack vulnerability

by aa, (4032 days ago) @ Jasmine

Hi!

I can find "SSH-2.0-WeOnlyDo 2.1.3" from freeSSHd software. Could you confirm is the library provided by you (SSH-2.0-WeOnlyDo 2.1.3) affected for HeartBleed attack vulnerability?

Thanks

locked

HeartBleed attack vulnerability

by Jasmine, (4032 days ago) @ aa

Hi.

None of WeOnlyDo libraries are vulnerable to Heartbleed.

Hope this helps!
Kreso

locked