]> git.ipfire.org Git - ipfire-2.x.git/commit
openssl: Update to 1.0.2o
authorMichael Tremer <michael.tremer@ipfire.org>
Tue, 27 Mar 2018 15:05:07 +0000 (16:05 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Tue, 27 Mar 2018 15:05:07 +0000 (16:05 +0100)
commit76f422025ffe1baed977b5c8e1f072e5981e46ff
tree1d18577f07bde51541ee3ac1f7e4094cd1503e20
parent166ceacd6b375bc97eed722012a0f1fffd5a15e1
openssl: Update to 1.0.2o

CVE-2018-0739 (OpenSSL advisory) [Moderate severity] 27 March 2018:

Constructed ASN.1 types with a recursive definition (such as can be
found in PKCS7) could eventually exceed the stack given malicious
input with excessive recursion. This could result in a Denial Of
Service attack. There are no such structures used within SSL/TLS
that come from untrusted sources so this is considered safe.
Reported by OSS-fuzz.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
lfs/openssl-compat