openssl 0.9.7g-1ubuntu1.3 source package in Ubuntu

Changelog

openssl (0.9.7g-1ubuntu1.3) breezy-security; urgency=low

  * SECURITY UPDATE: Remote arbitrary code execution, remote DoS.
  * crypto/asn1/tasn_dec.c, asn1_d2i_ex_primitive(): Initialize 'ret' to avoid
    an infinite loop in some circumstances. [CVE-2006-2937]
  * ssl/ssl_lib.c, SSL_get_shared_ciphers(): Fix len comparison to correctly
    handle invalid long cipher list strings. [CVE-2006-3738]
  * ssl/s2_clnt.c, get_server_hello(): Check for NULL session certificate to
    avoid client crash with malicious server responses. [CVE-2006-4343]
  * Certain types of public key could take disproportionate amounts of time to
    process. Apply patch from Bodo Moeller to impose limits to public key type
    values (similar to Mozilla's libnss). Fixes CPU usage/memory DoS. [CVE-2006-2940]
  * Updated patch in previous package version to fix a few corner-case
    regressions. (This reverts the changes to rsa_eay.c/rsa.h/rsa_err.c, which
    were determined to not be necessary).

 -- Martin Pitt <email address hidden>   Wed, 27 Sep 2006 10:51:00 +0000

Upload details

Uploaded by:
Martin Pitt
Uploaded to:
Breezy
Original maintainer:
Christoph Martin
Architectures:
any
Section:
utils
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssl_0.9.7g.orig.tar.gz 3.0 MiB e7e1a287141dd1be7f4b4fedd54ec29fa904655ed76a13ac87ae69a3fc76b062
openssl_0.9.7g-1ubuntu1.3.diff.gz 31.5 KiB 3dcce9e1247a7f0a764f2a0ab49d334d230fb81100a7ca62acab38d713e6bf59
openssl_0.9.7g-1ubuntu1.3.dsc 657 bytes 239a08618e5a7433f468207c9cc94d4b9ad3c069bc99de90a686f91cd0d7363b

View changes file

Binary packages built by this source

libcrypto0.9.7-udeb: No summary available for libcrypto0.9.7-udeb in ubuntu breezy.

No description available for libcrypto0.9.7-udeb in ubuntu breezy.

libssl-dev: No summary available for libssl-dev in ubuntu breezy.

No description available for libssl-dev in ubuntu breezy.

libssl0.9.7: No summary available for libssl0.9.7 in ubuntu breezy.

No description available for libssl0.9.7 in ubuntu breezy.

openssl: No summary available for openssl in ubuntu breezy.

No description available for openssl in ubuntu breezy.