Format: 1.8 Date: Tue, 18 Dec 2018 13:26:33 +0000 Source: openssl Binary: openssl libssl1.1 libcrypto1.1-udeb libssl1.1-udeb libssl-dev libssl-doc Architecture: source Version: 1.1.1a-2+ubuntu14.04.1+deb.sury.org+1 Distribution: trusty Urgency: high Maintainer: Debian OpenSSL Team Changed-By: Ondřej Surý Description: libcrypto1.1-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl-doc - Secure Sockets Layer toolkit - development documentation libssl1.1 - Secure Sockets Layer toolkit - shared libraries libssl1.1-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Closes: 465248 630790 736772 745657 759811 767207 768476 773601 782492 788511 794326 802591 813191 816239 823774 827028 839575 843064 844234 844715 848957 852017 852900 852920 859191 860254 861145 863367 863707 864080 867240 869856 875423 878303 882007 888305 891570 891797 892276 894282 895844 907631 910459 911389 912067 913558 Changes: openssl (1.1.1a-2+ubuntu14.04.1+deb.sury.org+1) trusty; urgency=medium . [ Sebastian Andrzej Siewior ] * Add Breaks on lighttpd (Closes: #913558). . [ Ondřej Surý ] * No-change backport to trusty . openssl (1.1.1a-1) unstable; urgency=medium . * Add Breaks on python-boto (See: #909545) * New upstream version - CVE-2018-0734 (Timing vulnerability in DSA signature generation) - CVE-2018-0735 (Timing vulnerability in ECDSA signature generation) - Update symbol file for 1.1.1a . openssl (1.1.1-2) unstable; urgency=medium . [ Sebastian Andrzej Siewior ] * Add Breaks on isync (See: #906955) * Fix autopkgtest (Closes: #910459) . [ Kurt Roeckx ] * Add Breaks on python-imaplib2 (See: #907079) * Add news entry regarding default TLS version and security level (Closes: #875423, #907631, #911389, #912067). . openssl (1.1.1-1) unstable; urgency=medium . * New upstream version. - Update symbol file for 1.1.1 - CVE-2018-0732 (actually since pre8). * Add Breaks on python-httplib2 (See: #907278) * Add hardening=+all. * Update to policy 4.2.1 - Less verbose testsuite with terse - Use RRR=no . openssl (1.1.1~~pre9-1) unstable; urgency=medium . * New upstream version. - Support the final TLS 1.3 version (RFC 8446) * Upload to unstable . openssl (1.1.1~~pre8-1) experimental; urgency=medium . * New upstream version. . openssl (1.1.1~~pre7-1) experimental; urgency=medium . * Drop afalgeng on kfreebsd-* which go enabled because they inherit from the linux target. * Fix debian-rules-sets-dpkg-architecture-variable. * Update to policy 4.1.4 - only Suggest: libssl-doc instead Recommends (only documentation and example code is shipped). - drop Priority: important. - use signing-key.asc and a https links for downloads * Use compat 11. - this moves the examples to /usr/share/doc/libssl-{doc->dev}/demos but it seems to make sense. * Add a 25-test_verify.t for autopkgtest which runs against intalled openssl binary. * Fix CVE-2018-0737 (Closes: #895844). . openssl (1.1.1~~pre6-2) experimental; urgency=medium . * Update libssl1.1.symbols . openssl (1.1.1~~pre6-1) experimental; urgency=medium . * New upstream version * Increase default security level from 1 to 2. This moves from the 80 bit security level to the 112 bit securit level and will require 2048 bit RSA and DHE keys. . openssl (1.1.1~~pre4-1) experimental; urgency=medium . * Update to 1.1.1-pre4 (Closes: #892276, #894282). * Add riscv64 target (Closes: #891797). . openssl (1.1.1~~pre3-1) experimental; urgency=medium . * Update to 1.1.1-pre3 * Don't suggest 1024 bit RSA key to be typical (Closes: #878303). * Don't insist on TLS1.3 cipher for * Add a udeb for libssl, based on similar changes done in Ubuntu starting in version 0.9.8o-4ubuntu1 (Closes: #802591) Patch from Margarita Manterola * Add support for nios2 (Closes: #816239) Based on patch from Marek Vasut * Update Spanish translation from Manuel "Venturi" Porras Peralta (Closes: #773601) * Don't build an i586 optimized version anymore, the default already targets that. Patch from Sven Joachim (Closes: #759811) . openssl (1.0.2g-1) unstable; urgency=high . * New upstream version * Fix CVE-2016-0797 * Fix CVE-2016-0798 * Fix CVE-2016-0799 * Fix CVE-2016-0702 * Fix CVE-2016-0705 * Disable EXPORT and LOW ciphers: The DROWN attack (CVE-2016-0800) makes use of those, and SLOTH attack (CVE-2015-7575) can make use of them too. . openssl (1.0.2f-2) unstable; urgency=high . * New upstream version. - Fixes CVE-2016-0701 - Not affected by CVE-2015-3197 because SSLv2 is disabled. . openssl (1.0.2e-1) unstable; urgency=high . * New upstream release - Fix CVE-2015-3193 - Fix CVE-2015-3194 - Fix CVE-2015-3195 - Fix CVE-2015-3196 * Remove all symlinks during clean * Run make depend after configure * Remove openssl_button.* from the doc package . openssl (1.0.2d-3) unstable; urgency=medium . * Upload to unstable . openssl (1.0.2d-2) experimental; urgency=medium . * Build with no-ssl3-method to remove all SSLv3 support. This results in the functions SSLv3_method(), SSLv3_server_method() and SSLv3_client_method() being removed from libssl. Change the soname as result of that and also changes name of the binary package. (Closes: #768476) * Enable rfc3779 and cms support (Closes: #630790) * Fix cross compilation for mips architectures. (Closes: #782492) . openssl (1.0.2d-1) unstable; urgency=high . * New upstream version - Fixes CVE-2015-1793 . openssl (1.0.2c-1) unstable; urgency=medium . * New upstream version - Fixes ABI (Closes: #788511) . openssl (1.0.2b-1) unstable; urgency=high . * New upstream version - Fix CVE-2015-4000 - Fix CVE-2015-1788 - Fix CVE-2015-1789 - Fix CVE-2015-1790 - Fix CVE-2015-1792 - Fix CVE-2015-1791 * Update c_rehash-compat.patch to make it apply to the new version. * Remove openssl-pod-misspell.patch applied upstream . openssl (1.0.2a-1) unstable; urgency=medium . * New upstrema version - Fix CVE-2015-0286 - Fix CVE-2015-0287 - Fix CVE-2015-0289 - Fix CVE-2015-0293 (not affected, SSLv2 disabled) - Fix CVE-2015-0209 - Fix CVE-2015-0288 - Fix CVE-2015-0291 - Fix CVE-2015-0290 - Fix CVE-2015-0207 - Fix CVE-2015-0208 - Fix CVE-2015-1787 - Fix CVE-2015-0285 * Temporary enable SSLv3 methods again, but they will go away. * Don't set TERMIO anymore, use the default TERMIOS instead. . openssl (1.0.2-1) experimental; urgency=medium . * New upstream release - Fixes CVE-2014-3571 - Fixes CVE-2015-0206 - Fixes CVE-2014-3569 - Fixes CVE-2014-3572 - Fixes CVE-2015-0204 - Fixes CVE-2015-0205 - Fixes CVE-2014-8275 - Fixes CVE-2014-3570 - Drop git_snapshot.patch * Drop gnu_source.patch, dgst_hmac.patch, stddef.patch, no_ssl3_method.patch: applied upstream * Update patches to apply . openssl (1.0.2~beta3-1) experimental; urgency=low . * New usptream beta version * Add git snapshot * Merge changes between 1.0.1h-3 and 1.0.1j-1: - Disables SSLv3 because of CVE-2014-3566 * Drop patch rehash-crt.patch: partially applied upstream. c_rehash now doesn't support files in DER format anymore. * Drop patch rehash_pod.patch: applied upstream * Update c_rehash-compat.patch to apply to new upstream version. This undoes upstream's "-old" option and creates both the new and old again. It now also does it for CRLs. * Drop defaults.patch, applied upstream * dgst_hmac.patch updated to apply to upstream version. * engines-path.patch updated to apply to upstream version. * Update list of exported symbols * Update symbols files to require beta3 * Enable unit tests * Add patch to add support for the no-ssl3-method option that completly disable SSLv3 and pass the option. This drops the following functions from the library: SSLv3_method, SSLv3_server_method and SSLv3_client_method * Build using OPENSSL_NO_BUF_FREELISTS . openssl (1.0.2~beta2-1) experimental; urgency=medium . * New usptream beta version - Fix CVE-2014-0224 - Fix CVE-2014-0221 - Fix CVE-2014-0195 - Fix CVE-2014-3470 - Fix CVE-2014-0198 - Fix CVE-2010-5298 - Fix CVE-2014-0160 - Fix CVE-2014-0076 * Merge changes between 1.0.1f-1 and 1.0.1h-3: - postinst: Updated check for restarting services * libdoc-manpgs-pod-spell.patch and openssl-pod-misspell.patch partially applied upstream * Drop fix-pod-errors.patch, applied upstream. * Add support for ppc64le (Closes: #745657) * Add support for OpenRISC (Closes: #736772) . openssl (1.0.2~beta1-1) experimental; urgency=medium . * New upstream beta version - Update list of symbols that should be exported and adjust the symbols file. This also removes a bunch of duplicate symbols in the linker file. - Fix additional pod errors - Following patches have been applied upstream and are removed: libssl-misspell.patch, pod_req_misspell2.patch, pod_pksc12.misspell.patch, pod_s_server.misspell.patch, pod_x509setflags.misspell.patch, pod_ec.misspell.patch, pkcs12-doc.patch, req_bits.patch - Following patches have been partially applied upstream: libdoc-manpgs-pod-spell.patch, openssl-pod-misspell.patch - Remove openssl_fix_for_x32.patch, different patch applied upstream. * Add support for cross compiling (Closes: #465248) Checksums-Sha1: 635d7855e99c88719c6995f103d6326637939974 2612 openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1.dsc 8fae27b4f34445a5500c9dc50ae66b4d6472ce29 8350547 openssl_1.1.1a.orig.tar.gz b141c8c9cd1b18f4a47e5f50c01ca8476cf53aa6 83472 openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1.debian.tar.xz 291e27365e63fec7a980b890c796475152e0efc2 6369 openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1_source.buildinfo Checksums-Sha256: 454d04fb46b76a69635e572754d82ed8081176b458ee26795d9f4a7caddb3b44 2612 openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1.dsc fc20130f8b7cbd2fb918b2f14e2f429e109c31ddd0fb38fc5d71d9ffed3f9f41 8350547 openssl_1.1.1a.orig.tar.gz 7f9cfb09997bac3e67eb28533feb84a9588016ff27b12c1a2c0b6a25b0af3527 83472 openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1.debian.tar.xz d6a646c49f15d09c5186ff07ca9a22339755313c5b2f29f30ab408340240f6b5 6369 openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1_source.buildinfo Files: c3c245730cdba3b8611e7599cad931a7 2612 utils optional openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1.dsc 963deb2272d6be7d4c2458afd2517b73 8350547 utils optional openssl_1.1.1a.orig.tar.gz dba38fdb303806bda6950b97228554aa 83472 utils optional openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1.debian.tar.xz 0de56a29e7dc079e008333f321e34177 6369 utils optional openssl_1.1.1a-2+ubuntu14.04.1+deb.sury.org+1_source.buildinfo