Backport of SSL fix (CVE-2014-0160) for 0.8.6 #4026

issue h0jeZvgoxFepBQ2C opened this issue on April 8, 2014
  1. h0jeZvgoxFepBQ2C commented at 9:34 PM on April 8, 2014: none

    Can you maybe publish a fixed version for 0.8.6? 0.9 introduces some changes which affords some changes to my service, so i would be happy if you could publish a fixed 0.8.6 version?

    Thanks!!!

  2. h0jeZvgoxFepBQ2C renamed this:
    Backport of SSL fix (CVE-2014-0160) for 0.8
    Backport of SSL fix (CVE-2014-0160) for 0.8.6
    on Apr 8, 2014
  3. laanwj commented at 7:38 AM on April 9, 2014: member

    The pre-compiled 0.8.6 uses an old OpenSSL version (0.9.8k if I reember correctly), so it's not an issue there. If you built it yourself you can just upgrade your OS'es OpenSSL lib version.

  4. laanwj closed this on Apr 9, 2014

  5. luke-jr commented at 9:27 AM on April 9, 2014: member

    Actually, 0.8.x uses OpenSSL 1.0.1c, but since it doesn't have payment protocol support it's really not applicable anyway. It would only be a concern if you had the RPC server exposed to the internet with SSL enabled, but that's already a security hazard even besides Heartbleed. I'll probably include a fixed OpenSSL in 0.8.7rc2, but it's not a priority and may never get built anyway since 0.9.0 is better in every way.

    What kind of problems do you have with 0.9.0? I don't recall any changes that should have broken compatibility with anything...

  6. h0jeZvgoxFepBQ2C commented at 9:47 AM on April 9, 2014: none

    I don't know, I just read that bitcoin qt is now splitted up into an cli version and i think i have to change some small parts of my monit scripts... Nothing big, but I have to spend some time.. a 0.8.7 version i probably could just drop in... but thanks anyway for the informations...

  7. gmaxwell commented at 9:54 AM on April 9, 2014: contributor

    @lichtamberg Nothing has changed there. There are new commands but the old things work like they always have, at least for now.

  8. laanwj reopened this on Apr 9, 2014

  9. laanwj commented at 10:33 AM on April 9, 2014: member

    Ok, reopening this issue then. I thought 0.8.x still used the old deps. But looking at the deps in 0.8.6 you are right: https://github.com/bitcoin/bitcoin/blob/0.8.6/contrib/gitian-descriptors/deps-win32.yml

  10. laanwj commented at 7:18 AM on May 2, 2014: member

    As 0.8.x doesn't fetch payment requests, there is only very little risk due to heartbleed: only if you have enabled -rpcssl, a host that is in already the -rpcallow list could execute the attack.

    After the initial hysteria has faded, it does not seem worth it to keep open this issue.

  11. laanwj closed this on May 2, 2014

  12. DrahtBot locked this on Sep 8, 2021

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-04-29 15:15 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me