OpenSSL 'Heartbleed' vulnerability

Posted: Wed Apr 09, 2014 10:16 am
by steve

The more observant amongst you will know that Cumulus uses OpenSSL client libraries (libeay32.dll and ssleay32.dll). These are used for connections to Twitter. It's not clear to me exactly how client libraries are affected (as opposed to servers) but apparently, they are. However, Cumulus uses version 1.0.0 of the libraries, which do not have the bug.