OpenSSL Key Recovery Attack on DH small subgroups (CVE-2016-0701)
intothesymmetry.blogspot.com
intothesymmetry.blogspot.com
That said, it's a serious issue, no doubt about that.
I would LOVE a clear "should I do emergency patching? yes/no" it seems like it would be frequently (maybe not always?) something that could be added to an announcement.
https://boringssl.googlesource.com/boringssl/+/9f226a5f5183e...
i.e. I've run openssl dhparam -out dhparam.pem 4096 on a potentially vulnerable version of OpenSSL.
Shouldn't that be "... do NOT ..."?
Edit: Nevermind the double negative got me. Setting the option (which is not on by default) mitigates the issue and they're saying many apps do set it.