I know that 13.04 is affected (or at least my installation is) because of the OpenSSL version currently installed. However, after running
sudo apt-get update
sudo apt-get upgrade
I checked my OpenSSL version and it was still an unpatched build.
I also checked http://www.ubuntu.com/usn/usn-2165-1/ and 13.04 isn't listed. What can I do to patch OpenSSL on my machine?
Note that 13.04 is no longer supported. Upgrading to a supported version is the recommended action. But if a short term solution is needed, it's possible to rebuild the packages from source (sample instructions) with a patch applied, e.g.:
From the Ubuntu changelog page for openssl, find the diff file for quantal, which happens to have the same base version of openssl (1.0.1c). This should apply cleanly against the latest source for raring. If following the instructions from the link above, apply the patch after doing the
dch -i
part, choose a sensible version number. Ignore/delete the rejected patch fordebian/changelog
, and continue the process.