openssl 0.9.8a-7ubuntu0.7 source package in Ubuntu

Changelog

openssl (0.9.8a-7ubuntu0.7) dapper-security; urgency=low

  * SECURITY UPDATE: crash via invalid memory access when printing BMPString
    or UniversalString with invalid length
    - crypto/asn1/tasn_dec.c, crypto/asn1/asn1_err.c and crypto/asn1/asn1.h:
      return error if invalid length
    - CVE-2009-0590
    - http://www.openssl.org/news/secadv_20090325.txt
    - patch from upstream CVS:
      crypto/asn1/asn1.h:1.128.2.11->1.128.2.12
      crypto/asn1/asn1_err.c:1.54.2.4->1.54.2.5
      crypto/asn1/tasn_dec.c:1.26.2.10->1.26.2.11

 -- Jamie Strandboge <email address hidden>   Thu, 26 Mar 2009 14:14:26 -0500

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Dapper
Original maintainer:
Debian OpenSSL Team
Architectures:
any
Section:
utils
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssl_0.9.8a.orig.tar.gz 3.1 MiB 30f8f61fb1316f4fb51410c740b4879b8e26b417c8d870e486144b10b8041c73
openssl_0.9.8a-7ubuntu0.7.diff.gz 50.2 KiB c6d01db0aaeba86ae12fda0ec0bd90bf49abb69b0b8675432a68ce0f03f3634a
openssl_0.9.8a-7ubuntu0.7.dsc 822 bytes 4d60ee3b675176baf87ec7b0351a3df239833b9b28e533a98a8c54a117d22130

View changes file

Binary packages built by this source

libcrypto0.9.8-udeb: No summary available for libcrypto0.9.8-udeb in ubuntu dapper.

No description available for libcrypto0.9.8-udeb in ubuntu dapper.

libssl-dev: No summary available for libssl-dev in ubuntu dapper.

No description available for libssl-dev in ubuntu dapper.

libssl0.9.8: No summary available for libssl0.9.8 in ubuntu dapper.

No description available for libssl0.9.8 in ubuntu dapper.

libssl0.9.8-dbg: No summary available for libssl0.9.8-dbg in ubuntu dapper.

No description available for libssl0.9.8-dbg in ubuntu dapper.

openssl: No summary available for openssl in ubuntu dapper.

No description available for openssl in ubuntu dapper.