openssl 1.0.1f-1ubuntu9 source package in Ubuntu

Changelog

openssl (1.0.1f-1ubuntu9) utopic; urgency=medium

  * SECURITY UPDATE: denial of service via DTLS SRTP memory leak
    - debian/patches/CVE-2014-3513.patch: fix logic in ssl/d1_srtp.c,
      ssl/srtp.h, ssl/t1_lib.c, util/mk1mf.pl, util/mkdef.pl,
      util/ssleay.num.
    - CVE-2014-3513
  * SECURITY UPDATE: denial of service via session ticket integrity check
    memory leak
    - debian/patches/CVE-2014-3567.patch: perform cleanup in ssl/t1_lib.c.
    - CVE-2014-3567
  * SECURITY UPDATE: fix the no-ssl3 build option
    - debian/patches/CVE-2014-3568.patch: fix conditional code in
      ssl/s23_clnt.c, ssl/s23_srvr.c.
    - CVE-2014-3568
  * SECURITY IMPROVEMENT: Added TLS_FALLBACK_SCSV support to mitigate a
    protocol downgrade attack to SSLv3 that exposes the POODLE attack.
    - debian/patches/tls_fallback_scsv_support.patch: added support for
      TLS_FALLBACK_SCSV in apps/s_client.c, crypto/err/openssl.ec,
      ssl/d1_lib.c, ssl/dtls1.h, ssl/s23_clnt.c, ssl/s23_srvr.c,
      ssl/s2_lib.c, ssl/s3_enc.c, ssl/s3_lib.c, ssl/ssl.h, ssl/ssl3.h,
      ssl/ssl_err.c, ssl/ssl_lib.c, ssl/t1_enc.c, ssl/tls1.h,
      doc/apps/s_client.pod, doc/ssl/SSL_CTX_set_mode.pod.
 -- Marc Deslauriers <email address hidden>   Thu, 16 Oct 2014 10:56:10 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Utopic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssl_1.0.1f.orig.tar.gz 4.3 MiB 6cc2a80b17d64de6b7bac985745fdaba971d54ffd7d38d3556f998d7c0c9cb5a
openssl_1.0.1f-1ubuntu9.debian.tar.xz 137.3 KiB e7073751d4cbdbdfc5ddd653efb8e30ae8ca5cf07e3b75d4947d5d492ceb0c71
openssl_1.0.1f-1ubuntu9.dsc 2.4 KiB 9a03b6feec279cb11555b876d88cb69cb6b67c753edd38c6a8540122193ffdd7

View changes file

Binary packages built by this source

libcrypto1.0.0-udeb: No summary available for libcrypto1.0.0-udeb in ubuntu utopic.

No description available for libcrypto1.0.0-udeb in ubuntu utopic.

libssl-dev: No summary available for libssl-dev in ubuntu utopic.

No description available for libssl-dev in ubuntu utopic.

libssl-doc: No summary available for libssl-doc in ubuntu vivid.

No description available for libssl-doc in ubuntu vivid.

libssl1.0.0: No summary available for libssl1.0.0 in ubuntu utopic.

No description available for libssl1.0.0 in ubuntu utopic.

libssl1.0.0-dbg: No summary available for libssl1.0.0-dbg in ubuntu vivid.

No description available for libssl1.0.0-dbg in ubuntu vivid.

libssl1.0.0-udeb: No summary available for libssl1.0.0-udeb in ubuntu vivid.

No description available for libssl1.0.0-udeb in ubuntu vivid.

openssl: No summary available for openssl in ubuntu utopic.

No description available for openssl in ubuntu utopic.