Ubuntu

“openssl” 1.0.0e-2ubuntu4.7 source package in The Oneiric Ocelot

Publishing history

1.0.0e-2ubuntu4.7
PUBLISHED: Oneiric pocket Updates in component main and section utils
  • Published on 2013-02-21
  • Copied from ubuntu oneiric in Private PPA for Ubuntu Security Team by Ubuntu Archive Robot
1.0.0e-2ubuntu4.7
PUBLISHED: Oneiric pocket Security in component main and section utils
  • Published on 2013-02-21
  • Copied from ubuntu oneiric in Private PPA for Ubuntu Security Team by Marc Deslauriers

Builds

Changelog

openssl (1.0.0e-2ubuntu4.7) oneiric-security; urgency=low

  * SECURITY UPDATE: denial of service via invalid OCSP key
    - debian/patches/CVE-2013-0166.patch: properly handle NULL key in
      crypto/asn1/a_verify.c, crypto/ocsp/ocsp_vfy.c.
    - CVE-2013-0166
  * SECURITY UPDATE: "Lucky Thirteen" timing side-channel TLS attack
    - debian/patches/CVE-2013-0169.patch: massive code changes
    - CVE-2013-0169
 -- Marc Deslauriers <email address hidden>   Mon, 18 Feb 2013 14:55:40 -0500