potentially vulnerable to cve-2009-3555
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Won't Fix
|
High
|
Robert Collins | ||
Ubuntu Website - OBSOLETE |
Won't Fix
|
Undecided
|
The Canonical Sysadmins | ||
Ubuntu |
Invalid
|
Undecided
|
Unassigned |
Bug Description
Symptoms
========
Using firefox open http://
You will see this message:
site : potentially vulnerable to cve-2009-3555
Cause
=====
We have disabled part of the TLS in order to prevent being affected by the mentioned CVE - launchpad is not vulnerable, and the browser warning is spurious : https:/
We will in due course have a newer libopenssl deployed onto our servers, but as this is, at most, cosmetic we're not planning on a special deployment for the moment - we will run with the version that is in Ubuntu's current LTS release. As of August 2010 Launchpad is about to upgrade to Lucid, which may give us the newer libopenssl.
Workaround
==========
Ignore the warning in your browser.
CVE References
affects: | launchpad → launchpad-foundations |
Changed in launchpad-foundations: | |
assignee: | nobody → Robert Collins (lifeless) |
Changed in launchpad-foundations: | |
status: | Triaged → Won't Fix |
description: | updated |
Changed in ubuntu-website: | |
status: | New → Won't Fix |
This is if I understand it correctly problem at those sites and not Ubuntu itself. I have assigned launchpad to this how to deal with wiki.ubuntu.com?