Overview

Request 155588 accepted

- Updated to 1.0.0k security release. bnc#802648 bnc#802746

To avoid backporting the large fixes for
SSL, TLS and DTLS Plaintext Recovery Attack (CVE-2013-0169)
TLS 1.1 and 1.2 AES-NI crash (CVE-2012-2686)
OCSP invalid key DoS issue (CVE-2013-0166)
- update to latest stable version 1.0.0i
including the following patches:
CVE-2012-2110.patch
Bug748738_Tolerate_bad_MIME_headers.patch
bug749213-Free-headers-after-use.patch
bug749210-Symmetric-crypto-errors-in-PKCS7_decrypt.patch
CVE-2012-1165.patch
CVE-2012-0884.patch
bug749735.patch
- Update to version 1.0.0g fix the following:
DTLS DoS attack (removed CVE-2012-0050.patch)
- Update to version 1.0.0f fix the following:
DTLS Plaintext Recovery Attack (removed CVE-2011-4108.patch)
Uninitialized SSL 3.0 Padding (removed CVE-2011-4576.patch)
Malformed RFC 3779 Data Can Cause Assertion Failures (removed CVE-2011-4577.patch)
SGC Restart DoS Attack (removed CVE-2011-4619.patch)
Invalid GOST parameters DoS Attack (removed CVE-2012-0027.patch)

- fix bug[ bnc#757773] - c_rehash to accept more filename extensions
Add patch file: openssl-1.0.0-c_rehash_accept_file_exts.patch

Request History
Marcus Meissner's avatar

msmeissn created request

- Updated to 1.0.0k security release. bnc#802648 bnc#802746

To avoid backporting the large fixes for
SSL, TLS and DTLS Plaintext Recovery Attack (CVE-2013-0169)
TLS 1.1 and 1.2 AES-NI crash (CVE-2012-2686)
OCSP invalid key DoS issue (CVE-2013-0166)
- update to latest stable version 1.0.0i
including the following patches:
CVE-2012-2110.patch
Bug748738_Tolerate_bad_MIME_headers.patch
bug749213-Free-headers-after-use.patch
bug749210-Symmetric-crypto-errors-in-PKCS7_decrypt.patch
CVE-2012-1165.patch
CVE-2012-0884.patch
bug749735.patch
- Update to version 1.0.0g fix the following:
DTLS DoS attack (removed CVE-2012-0050.patch)
- Update to version 1.0.0f fix the following:
DTLS Plaintext Recovery Attack (removed CVE-2011-4108.patch)
Uninitialized SSL 3.0 Padding (removed CVE-2011-4576.patch)
Malformed RFC 3779 Data Can Cause Assertion Failures (removed CVE-2011-4577.patch)
SGC Restart DoS Attack (removed CVE-2011-4619.patch)
Invalid GOST parameters DoS Attack (removed CVE-2012-0027.patch)

- fix bug[ bnc#757773] - c_rehash to accept more filename extensions
Add patch file: openssl-1.0.0-c_rehash_accept_file_exts.patch


Marcus Meissner's avatar

msmeissn accepted request

ok

openSUSE Build Service is sponsored by