openssl CVE fix question

Solution In Progress - Updated -

Issue

  • Our product use RHEL 5.11 at present, and the newest openssl RPM package is openssl-0.9.8e-36.el5_11.x86_64.rpm. We found that there are a lots of reported CVE already fixed by openssl.org, but not released the newest openssl RPM for RHEL 5.11 from Red Hat official.
  • For example: CVE-2015-1788, CVE-2015-1792, CVE-2015-1791 and so on
  • How can we get the fixed openssl RPM packages for RHEL 5.11?
  • Can we download the latest openssl source from openssl.org and compile it by ourself, then patch to our product is OK? Do this way has any impact for the OS of our product?

Environment

  • Red Hat Enterprise Linux (RHEL) 5

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.