OpenSSL "Heartbleed" bug

Discussion in 'Announcements, news, blog posts' started by mjp, Apr 9, 2014.

  1. mjp

    mjp

    It's hard to ignore all the news today related to the "Heartbleed" bug that potentially affects - according to Netcraft - two thirds of the world's web servers!

    But you should be aware that IIS does not use the OpenSSL library, so your sites hosted at DiscountASP.NET and Everleap are not affected by the bug.

    But, just about everywhere else...ouch.
     
  2. mjp

    mjp

    As it turns out, php includes the OpenSSL library, so we'll be updating that to a secure version across all of the servers.
     
  3. mjp

    mjp

    As it further turns out...our implementation of php did not use a vulnerable version of openSSL. So forget what I said about updating. All's well and all has been well!
     
    martino and RayH like this.

Share This Page