English

ArcGIS 10.1 SP1 - 10.2.2 for (Desktop, Engine, Server) OpenSSL Update Patch

Summary

This patch addresses non-exploitable instances of the OpenSSL defect commonly called Heartbleed that may still exist in ArcGIS 10.1 Service Pack 1 through ArcGIS 10.2.2. While these are non-exploitable instances of OpenSSL, customers who run security scan software on these ArcGIS releases may still see false positives until this software patch has been installed.

Description

Introduction

Esri® announces the ArcGIS 10.1 SP1 - 10.2.2 for (Desktop, Engine, Server) OpenSSL Update Patch. This patch addresses non-exploitable instances of the OpenSSL defect commonly called Heartbleed that may still exist in ArcGIS 10.1 Service Pack 1 through ArcGIS 10.2.2. While these are non-exploitable instances of OpenSSL, customers who run security scan software on these ArcGIS releases may still see false positives until this software patch has been installed. (Note Esri strongly recommends customers using ArcGIS for Server on Linux at versions 10.2, 10.2.1, and 10.2.2 install the ArcGIS 10.2 - 10.2.2 for Server OpenSSL (Heartbleed) Patch.) This OpenSSL Update Patch deals specifically with the issues listed below under Issues Addressed with this Patch.


Issues Addressed with this patch


  • NIM101047 - Non-exploitable instances of OpenSSL in ArcGIS may trigger a "false positive" when scanned for OpenSSL Vulnerability CVE-2014-0160 (Heartbleed).

Installing this patch on Windows

Installation Steps:

ArcGIS for Desktop, Engine, or Server must be installed before installing this patch.

  1. Download the appropriate file for your environment to a location other than your ArcGIS installation location.

  2. Version 10.1 Service Pack 1   Checksum (Md5)
         
         ArcGIS Desktop Background
         Geoprocessing (64-bit)
    ArcGIS-101SP1-BGDT-OSSLU-Patch.msp D33AEC8FBCBA4AF8A666AD1BE2B23000
         
         ArcGIS Engine Background
         Geoprocessing (64-bit)
    ArcGIS-101SP1-BGE-OSSLU-Patch.msp DF4B35D03C85D9F4111333C53ED774F1
         
          ArcGIS for Desktop ArcGIS-101SP1-DT-OSSLU-Patch.msp 498845E1E1D958188C2A2A10245678DC
         
          ArcGIS Engine ArcGIS-101SP1-E-OSSLU-Patch.msp 6277CC4811BD69D229D1A92EAAAC180F
         
          ArcReader ArcGIS-101SP1-R-OSSLU-Patch.msp 9C187C83CD3AD4B169D40DC1B38B5EF9
         
          ArcGIS for Server ArcGIS-101SP1-S-OSSLU-Patch.msp 3D01849514BD2AD39B1A67CD366DDF50
         
    Version 10.1 Service Pack 1 QIP   Checksum (Md5)
         
         ArcGIS Desktop Background
         Geoprocessing (64-bit)
    ArcGIS-101SP1QIP-BGDT-OSSLU-Patch.msp F2BB49EA0D5C2F92D40DB22C65C4327E
         
         ArcGIS Engine Background
         Geoprocessing (64-bit)
    ArcGIS-101SP1QIP-BGE-OSSLU-Patch.msp C0C37E92BA7A7C3F785D8F7404C68A41
         
          ArcGIS for Desktop ArcGIS-101SP1QIP-DT-OSSLU-Patch.msp 23232FEEB02583054D171E77D6B8833B
         
          ArcGIS Engine ArcGIS-101SP1QIP-E-OSSLU-Patch.msp 6C069A897593340BE9AD947B7EE72BA7
         
          ArcReader ArcGIS-101SP1QIP-R-OSSLU-Patch.msp 07A5F36DD03869F75881ED3681C3AE84
         
          ArcGIS for Server ArcGIS-101SP1QIP-S-OSSLU-Patch.msp 4826A5E73ED6DF0181E1F45AD19C9ADD
         
    Version 10.2   Checksum (Md5)
         
         ArcGIS Desktop Background
         Geoprocessing (64-bit)
    ArcGIS-102-BGDT-OSSLU-Patch.msp 536257ED1BF6D9EFBE0C69CFA550CA89
         
         ArcGIS Engine Background
         Geoprocessing (64-bit)
    ArcGIS-102-BGE-OSSLU-Patch.msp 5030AABD519EE909FCE486FA77D998DE
         
          ArcGIS for Desktop ArcGIS-102-DT-OSSLU-Patch.msp 0A86E54FCE538970269FD2E441F49167
         
          ArcGIS Engine ArcGIS-102-E-OSSLU-Patch.msp 529C9EF982C659BCA68AA8B12E571204
         
          ArcReader ArcGIS-102-R-OSSLU-Patch.msp 147D84AC0B3455AE320533B6DD314F0A
         
          ArcGIS for Server ArcGIS-102-S-OSSLU-Patch.msp 63C8DC713E08592C7AD8744D0B779F11
         
    Version 10.2.1   Checksum (Md5)
         
         ArcGIS Desktop Background
         Geoprocessing (64-bit)
    ArcGIS-1021-BGDT-OSSLU-Patch.msp 0C2C65493DA1BBB9CD75D77380CDB723
         
         ArcGIS Engine Background
         Geoprocessing (64-bit)
    ArcGIS-1021-BGE-OSSLU-Patch.msp 1741E117BE391067952082510EEBD528
         
         ArcGIS for Desktop ArcGIS-1021-DT-OSSLU-Patch.msp 82695163147ADA49DB2C6BD9F0FB609D
         
          ArcGIS Engine ArcGIS-1021-E-OSSLU-Patch.msp F71324F3457F3777536BD41D48E91632
         
          ArcReader ArcGIS-1021-R-OSSLU-Patch.msp 57ECB18D9AFEBE4D1A405B24BAF799CF
         
          ArcGIS for Server ArcGIS-1021-S-OSSLU-Patch.msp 7D360DAEB59F45518B394970F0A383FB
         
    Version 10.2.2   Checksum (Md5)
         
         ArcGIS Desktop Background
         Geoprocessing (64-bit)
    ArcGIS-1022-BGDT-OSSLU-Patch.msp F4176ADE57D841FA95DBD471F210BB2B
         
         ArcGIS Engine Background
         Geoprocessing (64-bit)
    ArcGIS-1022-BGE-OSSLU-Patch.msp 6447C06202B4671BB9662340489A6A9C
         
          ArcGIS for Desktop ArcGIS-1022-DT-OSSLU-Patch.msp 74A3AB51B200C25526836C0EE723AEFF
         
          ArcGIS Engine ArcGIS-1022-E-OSSLU-Patch.msp 51FCDB6CDAA28979AEB6C5D989D7A4F6
         
          ArcReader ArcGIS-1022-R-OSSLU-Patch.msp EAE3A7ABD2FE157D6D721D1D80C992C9
         
          ArcGIS for Server ArcGIS-1022-S-OSSLU-Patch.msp 717E02B963294B272D2BACA935809C0A
         

  3. Make sure you have write access to your ArcGIS installation location.

  4. Double-click the appropriate setup <msp/exe> to start the setup process.

    NOTE: If double clicking on the MSP file does not start the setup installation, you can start the setup installation manually by using the following command:

    msiexec.exe /p [location of Patch]\ArcGIS-<Version>-<Product>-OSSLU-Patch.msp

Installing this patch on Linux


Installation Steps:


Complete the following install steps as the ArcGIS Install owner. The Install owner is the owner of the arcgis folder.

ArcGIS Engine or ArcGIS for Server must be installed before installing this patch.

  1. Download the appropriate file for your environment to a location other than your ArcGIS installation location.


    Version 10.1 Service Pack 1   Checksum (Md5)
         
          ArcGIS for Server ArcGIS-101SP1-S-OSSLU-Patch-lx.tar EE4D4F5B0C095AA70241A6C995519D83
         
    Version 10.1 Service Pack 1 QIP   Checksum (Md5)
         
          ArcGIS for Server ArcGIS-101SP1QIP-OSSLU-Patch-lx.tar CB3036A515BC71F3BFFE857AB8FF1079
         
    Version 10.2   Checksum (Md5)
         
          ArcGIS for Server Please see: ArcGIS 10.2 - 10.2.2 for Server OpenSSL (Heartbleed) Patch  
         
    Version 10.2.1   Checksum (Md5)
         
          ArcGIS for Server Please see: ArcGIS 10.2 - 10.2.2 for Server OpenSSL (Heartbleed) Patch  
         
    Version 10.2.2   Checksum (Md5)
         
          ArcGIS for Server       Please see: ArcGIS 10.2 - 10.2.2 for Server OpenSSL (Heartbleed) Patch  
         

  2. Make sure you have write access to your ArcGIS installation location, and that no one is using ArcGIS.

  3. Extract the specified tar file by typing:

    % tar -xvf ArcGIS-<Version>-<Product>-OSSLU-Patch-lx.tar

  4. Start the installation by typing:

    % ./applypatch

    This will start the dialog for the menu-driven installation procedure. Default selections are noted in parentheses ( ). To quit the installation procedure, type 'q' at any time.

Patch Updates

Check the Patches and Service Packs page periodically for the availability of additional patches. New information about this patch will be posted here.

August 12, 2014: The ArcGIS 10.2.2 for Server setup 'ArcGIS-1022-S-OSSLU-Patch.msp' was updated to fix an installation issue that only applies to a machine running a Japanese Windows Operating System (OS).

How to identify which ArcGIS products are installed

To determine which ArcGIS products are installed, choose the appropriate version of the PatchFinder utility for your environment and run it from your local machine. PatchFinder will list all products, hot fixes, and patches installed on your local machine.


Getting Help

Domestic sites, please contact Esri Technical Support at 1-888-377-4575, if you have any difficulty installing this patch. International sites, please contact your local Esri software distributor.