A security advisory has been published for openssl 0.9.8n and 1.0.0.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0742http://www.openssl.org/news/secadv_20100601.txtThe affected Cryptographic Message Syntax (CMS) functions have been added in openssl 0.9.8 but they are disabled by default in 0.9.8 versions. They have been enabled in openssl 1.0.0.
Airlock is not affected by CVE-2010-0742.
Airlock version | openssl version | conclusion |
4.2.0 and 4.2.1 | 0.9.8k | CMS is disabled -> not affected |
4.2.2 | 1.0.0a | fixed openssl -> not affected |
4.1-10.65-HF4115 and 4.1-11.29 | 0.9.8k | CMS is disabled -> not affected |
4.1-10.65 | 0.9.7k | does not contain CMS code -> not affected |
The CMS functions are relatively new and are today only used in S/MIME-context (encrypted/signed emails). Airlock does not use S/MIME.