Format: 1.7 Date: Wed, 06 Oct 2010 18:24:13 -0400 Source: openssl Binary: libssl-dev openssl libssl0.9.8-dbg libcrypto0.9.8-udeb libssl0.9.8 Architecture: i386 Version: 0.9.8a-7ubuntu0.13 Distribution: dapper Urgency: low Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Marc Deslauriers Description: libcrypto0.9.8-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl0.9.8 - SSL shared libraries libssl0.9.8-dbg - Symbol tables for libssl and libcrypt openssl - Secure Socket Layer (SSL) binary and related cryptographic tools Changes: openssl (0.9.8a-7ubuntu0.13) dapper-security; urgency=low . * SECURITY UPDATE: denial of service and possible code execution via unchecked bn_wexpand return values. (LP: #655884) - crypto/bn/{bn_mul,bn_div,bn_gf2m}.c, crypto/ec/ec2_smpl.c, engines/e_ubsec.c: check return values. - http://cvs.openssl.org/chngview?cn=18936 - http://cvs.openssl.org/chngview?cn=19309 - CVE-2009-3245 * SECURITY UPDATE: denial of service and possible code execution via crafted private key with an invalid prime. - ssl/s3_clnt.c: set bn_ctx to NULL after freeing it. - http://www.mail-archive.com/openssl-dev@openssl.org/msg28049.html - CVE-2010-2939 Files: 9bcd7c6ca5340d48bd37ef5b1ec0373b 988924 utils optional openssl_0.9.8a-7ubuntu0.13_i386.deb 45da91cc1a491b75e4d3d13dfc313486 2662124 libs important libssl0.9.8_0.9.8a-7ubuntu0.13_i386.deb 888c37f7cc3ac622cd178f201b8a5ba2 509640 debian-installer optional libcrypto0.9.8-udeb_0.9.8a-7ubuntu0.13_i386.udeb 6774e94d928da6c8c692b6cfcb198924 2037066 libdevel optional libssl-dev_0.9.8a-7ubuntu0.13_i386.deb e433673d391c7071aef4b30a4cb5cf0c 5193182 libdevel extra libssl0.9.8-dbg_0.9.8a-7ubuntu0.13_i386.deb Package-Type: udeb