Skip to content

Instantly share code, notes, and snippets.

  • Save softmonkeyjapan/cc7b9faec30ec9527d8ea0a936246db2 to your computer and use it in GitHub Desktop.
Save softmonkeyjapan/cc7b9faec30ec9527d8ea0a936246db2 to your computer and use it in GitHub Desktop.
Fix OpenSSL Padding Oracle vulnerability (CVE-2016-2107) - Ubuntu 14.04
# Based on http://fearby.com/article/update-openssl-on-a-digital-ocean-vm/
$ sudo apt-get update
$ sudo apt-get dist-upgrade
$ wget ftp://ftp.openssl.org/source/openssl-1.0.2h.tar.gz
$ tar -xvzf openssl-1.0.2h.tar.gz
$ cd openssl-1.0.2h
$ ./config --prefix=/usr/
$ make depend
$ sudo make install
$ openssl version
# OpenSSL 1.0.2h 3 May 2016
# now restart your nginx or other server
$ sudo service nginx restart
# check your website here https://www.ssllabs.com/ssltest/
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment