openssl security update
OpenSSL's internal certificate verification routines could
incorrectly accept a CRL whose nextUpdate field is in the
past (CVE-2011-3207).
Server code for ECDH could crash if it received a specially
crafted handshake message (CVE-2011-3210).
-
Submitted by
Adrian Schröter (adrianSuSE)
- Version 5178
Fixed bugs
bnc#716143
VUL-0: openssl CRL validation flaw
bnc#716144
VUL-0: openssl ECDH crash