Skip to content

Commit

Permalink
Blog: Update January OpenSSL post with releases
Browse files Browse the repository at this point in the history
PR-URL: #1120
  • Loading branch information
rvagg committed Feb 1, 2017
1 parent 34fad98 commit ed1fbf1
Showing 1 changed file with 16 additions and 0 deletions.
16 changes: 16 additions & 0 deletions locale/en/blog/vulnerability/openssl-january-2017.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,22 @@ layout: blog-post.hbs
author: Rod Vagg
---

## _(Update 1-February-2017)_ Releases available

Updates are now available for all active Node.js release lines.

The following releases are bundled with OpenSSL 1.0.2k:

* [Node.js 7.5.0 (Current)](https://nodejs.org/en/blog/release/v7.5.0/)
* [Node.js 6.9.5 (LTS "Boron")](https://nodejs.org/en/blog/release/v6.9.5/)
* [Node.js 4.7.3 (LTS "Argon")](https://nodejs.org/en/blog/release/v4.7.3/)

While this is not a critical update, all users of these release lines should upgrade at their earliest convenience.

***Original post is included below***

--------------------------------------

The OpenSSL project has [announced](https://mta.openssl.org/pipermail/openssl-announce/2017-January/000092.html) the immediate availability of OpenSSL version 1.0.2k.

Although the OpenSSL team have determined a maximum severity rating of "moderate", the Node.js crypto team (Ben Noordhuis, Shigeki Ohtsu and Fedor Indutny) have determined the impact to Node users is "low". Details on this determination can be found below.
Expand Down

0 comments on commit ed1fbf1

Please sign in to comment.