SimplerCloud Pte Ltd

×
×

News: Security Advisory: Heartbleed (Openssl 1.0.1)

Published: 08/04/2014 Back

We bring your attention to Heartbleed, a serious security vulnerability allowing anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. If you’re running a server with OpenSSL 1.0.1 through 1.0.1f, you should update to OpenSSL 1.0.1g immediately.


Update: All SimplerCloud customer-related systems, namely the account panel & web site, have been upgraded and are not vulnerable. You are advised to update your related servers as soon as possible.


This is a one-time courtesy notification and the following links are key references at this time. 


Official Page: heartbleed.com


OpenSSL notification


Fix from Ubuntu


Fix from CentOS (forum discussion and Redhat fix)


News: Heartbleed bug 


If you require assistance with this upgrade, we can provide it under our System Administration service.  Please first open a support ticket and give us the hostname, ip address and OS template.You can find this information on your servelet's control panel. For example: Hostname test-dd IP Address: 103.25.202.81 OS Template CentOS 6.5 (64-bit) 20140123a


To check the version of openssl:

- SSH to your servelet
- Type "openssl"
- on the OpenSSL> prompt, type version
- Type exit to go back to SSH prompt

For example:

root@joel [/home]# openssl
OpenSSL> version
OpenSSL 1.0.1e-fips 11 Feb 2013