openssl 0.9.8a-7ubuntu0.10 source package in Ubuntu

Changelog

openssl (0.9.8a-7ubuntu0.10) dapper-security; urgency=low

  * SECURITY UPDATE: certificate spoofing via hash collisions from MD2
    design flaws.
    - crypto/evp/c_alld.c, ssl/ssl_algs.c: disable MD2 digest.
    - crypto/x509/x509_vfy.c: skip signature check for self signed
      certificates
    - http://marc.info/?l=openssl-cvs&m=124508133203041&w=2
    - http://marc.info/?l=openssl-cvs&m=124704528713852&w=2
    - CVE-2009-2409

 -- Marc Deslauriers <email address hidden>   Tue, 08 Sep 2009 15:07:55 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Dapper
Original maintainer:
Debian OpenSSL Team
Architectures:
any
Section:
utils
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssl_0.9.8a.orig.tar.gz 3.1 MiB 30f8f61fb1316f4fb51410c740b4879b8e26b417c8d870e486144b10b8041c73
openssl_0.9.8a-7ubuntu0.10.diff.gz 52.6 KiB e39ef56ee8c166117d175aca2072c959039e0bb30a237081c0ad081dc24e30fb
openssl_0.9.8a-7ubuntu0.10.dsc 824 bytes 1bed258ee1e545968bf493f89871c9501ee06d4165598e2414656abe74136d7c

View changes file

Binary packages built by this source

libcrypto0.9.8-udeb: No summary available for libcrypto0.9.8-udeb in ubuntu dapper.

No description available for libcrypto0.9.8-udeb in ubuntu dapper.

libssl-dev: No summary available for libssl-dev in ubuntu dapper.

No description available for libssl-dev in ubuntu dapper.

libssl0.9.8: No summary available for libssl0.9.8 in ubuntu dapper.

No description available for libssl0.9.8 in ubuntu dapper.

libssl0.9.8-dbg: No summary available for libssl0.9.8-dbg in ubuntu dapper.

No description available for libssl0.9.8-dbg in ubuntu dapper.

openssl: No summary available for openssl in ubuntu dapper.

No description available for openssl in ubuntu dapper.