Embargoed OpenSSL Vulnerabilities
mta.openssl.org
mta.openssl.org
On RHEL/CentOS, you can use needs-restarting, to tell you what processes need restarting after a lib update.
sudo yum update
sudo yum install yum-utils.noarch
sudo needs-restarting
On Debian/Ubuntu, you can use checkrestart, to tell you what processes need restarting after a lib update. sudo apt-get update
sudo apt-get upgrade
sudo apt-get install debian-goodies
sudo checkrestart -v
Helps to work through this manually, wrap your head around what needs to be done, then you can push that into automation tools if you have a large enough infrastructure. Here's a screencast about the pattern for anyone interested in learning more.[1] https://sysadmincasts.com/episodes/44-patching-the-ghost-gli...
https://www.openssl.org/about/secpolicy.html
high severity issues. This includes issues affecting common configurations which are also likely to be exploitable. Examples include a server DoS, a significant leak of server memory, and remote code execution. These issues will be kept private and will trigger a new release of all supported versions. We will attempt to keep the time these issues are private to a minimum; our aim would be no longer than a month where this is something under our control, and significantly quicker if there is a significant risk or we are aware the issue is being exploited.