How to reliably and portably check the OpenSSL version?
serverfault.com
serverfault.com
$ sudo apt-cache policy libssl1.0.0
You want to see version 1.0.1-4ubuntu5.12 which is the correct, patched version. Just updated two of my servers. dpkg -l libssl1.0.0
FYI: dpkg and apt-cache do not need to have elevated privileges to print the installed version.Basically 1.0.1-4ubuntu-5.12 is the version you want on ubuntu 12.04 (or 1.0.1-1ubuntu2 for 14.04), but openssl version doesn't report that.
Remember that the idea for the LTS releases is that as little as possible is changed ("stable") over a period of several years ("long term"). Upgrading to new versions of packages with new bugs^Wfeatures has the very real possibility of "breaking" stable environments.
Instead of doing that, they simply incorporate the patch/fix into the version of the software that the release shipped with. They can't, then, call it 1.0.1g because, well, it's not -- it is, for example, 1.0.1c with this patch applied.
It's for that reason that you can't trust the version numbers on the packages themselves.
(Several years ago, I would get really pissed off at Nessus because it generate false positives by simply looking at the version numbers of installed packages. These were scans of RHEL boxes as part of PCI and it caused a lot of extra work. I've no idea if Nessus still does that or not but I'm sure other, similar software does the same thing.)
http://aws.amazon.com/amazon-linux-ami/security-bulletins/AL...
echo | openssl s_client -tlsextdebug -connect host:443 | grep heartbeat
TLS server extension "heartbeat" (id=15), len=1