The OpenSSL cryptographic library, used by GemStone for RPC session logins (client-to-gem connections), has a security advisory for version 1.0.1h and earlier.
More information can be found at www.openssl.org/news/secadv/20140806.txt
This bug has been fixed in OpenSSL version 1.0.1i. GemStone uses OpenSSL as a shared library which can be replaced with minimal disruption; if you believe this bug is a significant risk, contact GemTalk Technical support for the GemTalk OpenSSL libraries for your platform.
Last updated: 8/31/15