openssl 0.9.8k-7ubuntu8.20 source package in Ubuntu

Changelog

openssl (0.9.8k-7ubuntu8.20) lucid-security; urgency=medium

  * SECURITY UPDATE: double free when processing DTLS packets
    - debian/patches/CVE-2014-3505.patch: fix double free in ssl/d1_both.c.
    - CVE-2014-3505
  * SECURITY UPDATE: DTLS memory exhaustion
    - debian/patches/CVE-2014-3506.patch: fix DTLS handshake message size
      checks in ssl/d1_both.c.
    - CVE-2014-3506
  * SECURITY UPDATE: information leak in pretty printing functions
    - debian/patches/CVE-2014-3508.patch: fix OID handling in
      crypto/asn1/a_object.c, crypto/objects/obj_dat.c, crypto/asn1/asn1.h,
      crypto/asn1/asn1_err.c.
    - CVE-2014-3508
  * SECURITY UPDATE: DTLS anonymous EC(DH) denial of service
    - debian/patches/CVE-2014-3510.patch: check for server certs in
      ssl/d1_clnt.c, ssl/s3_clnt.c.
    - CVE-2014-3510
  * SECURITY UPDATE: TLS protocol downgrade attack
    - debian/patches/CVE-2014-3511.patch: properly handle fragments in
      ssl/s23_srvr.c.
    - CVE-2014-3511
 -- Marc Deslauriers <email address hidden>   Thu, 07 Aug 2014 08:48:43 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Lucid
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssl_0.9.8k.orig.tar.gz 3.7 MiB 7e7cd4f3974199b729e6e3a0af08bd4279fde0370a1120c1a3b351ab090c6101
openssl_0.9.8k-7ubuntu8.20.diff.gz 155.6 KiB 902983f3c69433b3c47f0be1e33f907fe61e9252c9e04fd824e96547223c0678
openssl_0.9.8k-7ubuntu8.20.dsc 2.0 KiB 6fb39b2e7ae0a9615e80634da0e0c209b6c76dd92c45f4c92c32cfc22f76e415

Available diffs

View changes file

Binary packages built by this source

libcrypto0.9.8-udeb: No summary available for libcrypto0.9.8-udeb in ubuntu lucid.

No description available for libcrypto0.9.8-udeb in ubuntu lucid.

libssl-dev: No summary available for libssl-dev in ubuntu lucid.

No description available for libssl-dev in ubuntu lucid.

libssl0.9.8: No summary available for libssl0.9.8 in ubuntu lucid.

No description available for libssl0.9.8 in ubuntu lucid.

libssl0.9.8-dbg: No summary available for libssl0.9.8-dbg in ubuntu lucid.

No description available for libssl0.9.8-dbg in ubuntu lucid.

libssl0.9.8-udeb: No summary available for libssl0.9.8-udeb in ubuntu lucid.

No description available for libssl0.9.8-udeb in ubuntu lucid.

openssl: No summary available for openssl in ubuntu lucid.

No description available for openssl in ubuntu lucid.

openssl-doc: No summary available for openssl-doc in ubuntu lucid.

No description available for openssl-doc in ubuntu lucid.