openssl CVE fix question
Issue
- Our product use
RHEL 5.11at present, and the newestopensslRPM package isopenssl-0.9.8e-36.el5_11.x86_64.rpm. We found that there are a lots of reported CVE already fixed byopenssl.org, but not released the newestopensslRPM forRHEL 5.11from Red Hat official. - For example: CVE-2015-1788, CVE-2015-1792, CVE-2015-1791 and so on
- How can we get the fixed openssl RPM packages for RHEL 5.11?
- Can we download the latest
opensslsource fromopenssl.organd compile it by ourself, then patch to our product is OK? Do this way has any impact for the OS of our product?
Environment
- Red Hat Enterprise Linux (RHEL) 5
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
