We bring your attention to Heartbleed, a serious security vulnerability allowing anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. If you’re running a server with OpenSSL 1.0.1 through 1.0.1f, you should update to OpenSSL 1.0.1g immediately.
Update: All SimplerCloud customer-related systems, namely the account panel & web site, have been upgraded and are not vulnerable. You are advised to update your related servers as soon as possible.
This is a one-time courtesy notification and the following links are key references at this time.
Official Page: heartbleed.com
Fix from CentOS (forum discussion and Redhat fix)
News: Heartbleed bug
If you require assistance with this upgrade, we can provide it under our System Administration service. Please first open a support ticket and give us the hostname, ip address and OS template.You can find this information on your servelet's control panel. For example: Hostname test-dd IP Address: 103.25.202.81 OS Template CentOS 6.5 (64-bit) 20140123a
To check the version of openssl:
- SSH to your servelet
- Type "openssl"
- on the OpenSSL> prompt, type version
- Type exit to go back to SSH prompt
For example:
root@joel [/home]# openssl
OpenSSL> version
OpenSSL 1.0.1e-fips 11 Feb 2013