OpenSSL released a new version 1.0.1i. The update fixes several security issues. Airlock may be affected by two issues (CVE-2014-3511, CVE-2014-3509). The other 7 issues are related to the DTLS protocol or to the cipher suites SRP and aECDH which are by default not used by Airlock. We rate the criticality of the issues as moderate.
We recommend to update OpenSSL to version 1.0.1i with hotfix HF4226 for Airlock 4.2.6.x and HF5005 for Airlock 5.0, respectively. The hotfixes will be available within the next few days.