]> git.ipfire.org Git - people/trikolon/ipfire-2.x.git/commit
openssl: security update to 0.9.8w. (CVE-2012-2131).
authorArne Fitzenreiter <arne_f@ipfire.org>
Wed, 2 May 2012 17:42:02 +0000 (19:42 +0200)
committerArne Fitzenreiter <arne_f@ipfire.org>
Sat, 12 May 2012 17:28:24 +0000 (19:28 +0200)
commita6f4183e83385cbd21d31db07171fb7109b81d54
treebfe626821a540c832bda9aefe969d903a62f5ed2
parent75c2cf6f51d4f7d8e513b6df6a25b30e8a834f9f
openssl: security update to 0.9.8w. (CVE-2012-2131).

SN1 BIO incomplete fix (CVE-2012-2131)
=======================================

It was discovered that the fix for CVE-2012-2110 released on 19 Apr
2012 was not sufficient to correct the issue for OpenSSL 0.9.8.

Please see http://www.openssl.org/news/secadv_20120419.txt for details
of that vulnerability.

This issue only affects OpenSSL 0.9.8v.  OpenSSL 1.0.1a and 1.0.0i
already contain a patch sufficient to correct CVE-2012-2110.

Thanks to Red Hat for discovering and fixing this issue.

Affected users should upgrade to 0.9.8w.

References
==========

URL for this Security Advisory:
http://www.openssl.org/news/secadv_20120424.txt
config/rootfiles/common/openssl
lfs/openssl