HeartBleed attack vulnerability - WeOnlyDo Discussion board

HeartBleed attack vulnerability (General questions)

by Jan Manek, Thursday, April 10, 2014, 08:33 (3881 days ago)
edited by wodSupport, Thursday, April 10, 2014, 11:42

Hello,

we're using wodSSHServer/wodSSHClient components (different versions) in some of our products. I can see that for FIPS complaincy we need to provide for your component also libeay32.dll and ssleay32.dll libraries from OpenSLL.

Are your *SSH* components (and our customers) vulnerable against HeartBleed attack?

Thanks,
Jan Manek

HeartBleed attack vulnerability

by wodSupport, Thursday, April 10, 2014, 08:35 (3881 days ago) @ Jan Manek

Jan,

hi. We use OpenSSL version 0.9.8y so we're not affected by Heartbleed bug.

Hope this helps!
Kreso

HeartBleed attack vulnerability

by Jan Manek, Thursday, April 10, 2014, 08:53 (3881 days ago) @ wodSupport

Do you mean the latest version of SSH Server?

What about older versions? We're using that component for years and the customers can have installed older versions.

Thanks,
Jan Manek

HeartBleed attack vulnerability

by wodSupport, Thursday, April 10, 2014, 08:55 (3881 days ago) @ Jan Manek

Jan,

older version too, they used older 0.9.8 revisions then.

Kreso

HeartBleed attack vulnerability

by aa, Thursday, April 17, 2014, 14:04 (3873 days ago) @ wodSupport

Hi!

I can find "SSH-2.0-WeOnlyDo 2.1.3" from freeSSHd software. Could you confirm is the library provided by you (SSH-2.0-WeOnlyDo 2.1.3) affected for HeartBleed attack vulnerability?

Thanks

HeartBleed attack vulnerability

by wodSupport, Thursday, April 17, 2014, 14:19 (3873 days ago) @ aa

Hi.

None of WeOnlyDo libraries are vulnerable to Heartbleed.

Hope this helps!
Kreso