"openssl - 1.0.1e-4ubuntu4~linaro1 " and "libssl1.0.0_1.0.1e-4ubuntu4~linaro1" are affected by USN-2165-1 ("heartbleed")

Bug #1305000 reported by Hans-Richard Grube
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Linaro Ubuntu
New
Undecided
Unassigned

Bug Description

The following packages are affected by USN-2165-1 http://www.ubuntu.com/usn/usn-2165-1/ ("heartbleed"):

openssl-1.0.1e-4ubuntu4~linaro1: https://launchpad.net/~linaro-maintainers/+archive/overlay/+files/openssl_1.0.1e-4ubuntu4%7Elinaro1_armhf.deb
libssl1.0.0_1.0.1e-4ubuntu4~linaro1: https://launchpad.net/~linaro-maintainers/+archive/overlay/+files/libssl1.0.0_1.0.1e-4ubuntu4%7Elinaro1_armhf.deb

Official Ubuntu repos already provide a fix. Unfortunately, the ppa "Linaro Overlay PPA" makes apt skip the fix and instead installs the flawed version provided by this ppa.

description: updated
description: updated
summary: "openssl - 1.0.1e-4ubuntu4~linaro1 " and
"libssl1.0.0_1.0.1e-4ubuntu4~linaro1" are affected by USN-2165-1
+ ("heartbleed")
description: updated
information type: Private Security → Public
information type: Public → Public Security
information type: Public Security → Public
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.