openssl 0.9.8g-4ubuntu3.19 source package in Ubuntu


openssl (0.9.8g-4ubuntu3.19) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service attack in DTLS implementation
    - ssl/d1_enc.c: guard for integer overflow before skipping
      explicit IV
    - CVE-2012-2333
  * SECURITY UPDATE: million message attack (MMA) in CMS
    - crypto/pkcs7/pk7_doit.c: use a random key if RSA decryption
      fails to avoid leaking timing information
    - CVE-2012-0884
  * crypto/pkcs7/pk7_smime.c: detect symmetric crypto errors in
 -- Steve Beattie <email address hidden>   Tue, 22 May 2012 12:46:37 -0700

Upload details

Uploaded by:
Steve Beattie on 2012-05-22
Uploaded to:
Original maintainer:
Ubuntu Developers
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section


File Size MD5 Checksum
openssl_0.9.8g.orig.tar.gz 3.2 MiB acf70a16359bf3658bdfb74bda1c4419
openssl_0.9.8g-4ubuntu3.19.diff.gz 86.8 KiB 69414bbea8cf1a89ef38478138a7e0f3
openssl_0.9.8g-4ubuntu3.19.dsc 1.5 KiB 88cd7ede4bd9ff59f5ddc4d361f0515b

View changes file

Binary packages built by this source

libcrypto0.9.8-udeb: crypto shared library - udeb

 libcrypto shared library.
 Do not install it on a normal system.

libssl-dev: SSL development libraries, header files and documentation

 libssl and libcrypto development libraries, header files and manpages.
 It is part of the OpenSSL implementation of SSL.

libssl0.9.8: SSL shared libraries

 libssl and libcrypto shared libraries needed by programs like
 apache-ssl, telnet-ssl and openssh.
 It is part of the OpenSSL implementation of SSL.

libssl0.9.8-dbg: Symbol tables for libssl and libcrypto

 This package is part of the OpenSSL implementation of SSL.

openssl: Secure Socket Layer (SSL) binary and related cryptographic tools

 This package contains the openssl binary and related tools.
 It is part of the OpenSSL implementation of SSL.
 You need it to perform certain cryptographic actions like:
  - Creation of RSA, DH and DSA key parameters;
  - Creation of X.509 certificates, CSRs and CRLs;
  - Calculation of message digests;
  - Encryption and decryption with ciphers;
  - SSL/TLS client and server tests;
  - Handling of S/MIME signed or encrypted mail.

openssl-doc: Secure Socket Layer (SSL) documentation

 This package contains the OpenSSL documentation.
 It is part of the OpenSSL implementation of SSL.