[request] fast critical security updates [answered]

2014-11-27

Found that latest updated SailfishOS on jolla ( have outdated OpenSSL 1.0.1h while most recent version is openssl 1.0.1j

I think such critical component must be updated more quickly, like in any other popular linux distribution.

2014-11-28

All the _vulnerabilities_ fixed on that openssl version are server side issues. Sure there is support for TLS_FALLBACK_SCSV but it is only to be used by applications which support protocol fallback (and would require support from application side as well).

The next update will however include the "j"-update.

No matter client or server side, server side packages like openssh depends from openssl too. There may be user client and server apps as well.

lion ( 2014-11-30 )

