X-Git-Url: https://tinc-vpn.org/git/browse?a=blobdiff_plain;f=news%2Fheartbleed.mdwn;fp=news%2Fheartbleed.mdwn;h=2b47f42f0d251e3390cb0b30370019e6ffbd497f;hb=291b7b7d8d51993c6a6cfcd8e464c96555b04323;hp=0000000000000000000000000000000000000000;hpb=e50284820a4aae5b4503db026afc29330b2e0fb2;p=wiki diff --git a/news/heartbleed.mdwn b/news/heartbleed.mdwn new file mode 100644 index 0000000..2b47f42 --- /dev/null +++ b/news/heartbleed.mdwn @@ -0,0 +1,10 @@ +[[!meta author="guus"]] + +Tinc is *not vulnerable* to the Heartbleed bug. + +The [Hearbleed bug](http://heartbleed.com/) +([CVE-2014-0160](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160)) +is a bug in the [OpenSSL](https://en.wikipedia.org/wiki/Openssl) library that +affects any application which is linked to it and is making or accepting TLS +connections. Although tinc links to the OpenSSL library, it does not use the +TLS protocol, and is therefore not vulnerable.