- --- 9.9.8-P1 released ---
+ --- 9.9.8-P2 released ---
+
+4270. [security] Update allowed OpenSSL versions as named is
+ potentially vulnerable to CVE-2015-3193.
+
+4253. [security] Address fetch context reference count handling error
+ on socket error. (CVE-2015-8461) [RT#40945]
+
+ --- 9.9.8-P1 (withdrawn) ---
4261. [maint] H.ROOT-SERVERS.NET is 198.97.190.53 and 2001:500:1::53.
[RT #40556]
triggering a REQUIRE failure when those records
were subsequently cached. (CVE-2015-8000) [RT #40987]
-4253. [security] Address fetch context reference count handling error
- on socket error. (CVE-2015-8461) [RT#40945]
-
--- 9.9.8 released ---
--- 9.9.8rc1 released ---
int main() {
if ((OPENSSL_VERSION_NUMBER >= 0x009070cfL &&
OPENSSL_VERSION_NUMBER < 0x00908000L) ||
- OPENSSL_VERSION_NUMBER >= 0x0090804fL)
+ OPENSSL_VERSION_NUMBER >= 0x0090804fL &&
+ OPENSSL_VERSION_NUMBER < 0x10002000L) ||
+ OPENSSL_VERSION_NUMBER >= 0x1000205fL)
return (0);
printf("\n\nFound OPENSSL_VERSION_NUMBER %#010x\n",
OPENSSL_VERSION_NUMBER);
printf("Require OPENSSL_VERSION_NUMBER 0x009070cf or greater (0.9.7l)\n"
- "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n\n");
+ "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n"
+ "Require OPENSSL_VERSION_NUMBER 0x1000000f or greater (1.0.0)\n"
+ "Require OPENSSL_VERSION_NUMBER 0x1000100f or greater (1.0.1)\n"
+ "Require OPENSSL_VERSION_NUMBER 0x1000205f or greater (1.0.2e)\n\n");
return (1);
}
WARNING one or more of the the following known security WARNING
WARNING flaws: WARNING
WARNING WARNING
-WARNING CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and WARNING
-WARNING CVE-2006-2940. WARNING
+WARNING CAN-2002-0659, CAN-2006-4339, CVE-2006-2937, WARNING
+WARNING CVE-2006-2940 and CVE-2015-3193. WARNING
WARNING WARNING
WARNING It is recommended that you upgrade to OpenSSL WARNING
-WARNING version 0.9.8d/0.9.7l (or greater). WARNING
+WARNING version 1.0.2e/1.0.1/1.0.0/0.9.9/0.9.8d/0.9.7l WARNING
+WARNING (or greater). WARNING
WARNING WARNING
WARNING You can disable this warning by specifying: WARNING
WARNING WARNING
-WARNING --disable-openssl-version-check WARNING
+WARNING --disable-openssl-version-check WARNING
WARNING WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
int main() {
if ((OPENSSL_VERSION_NUMBER >= 0x009070cfL &&
OPENSSL_VERSION_NUMBER < 0x00908000L) ||
- OPENSSL_VERSION_NUMBER >= 0x0090804fL)
+ OPENSSL_VERSION_NUMBER >= 0x0090804fL &&
+ OPENSSL_VERSION_NUMBER < 0x10002000L) ||
+ OPENSSL_VERSION_NUMBER >= 0x1000205fL)
return (0);
printf("\n\nFound OPENSSL_VERSION_NUMBER %#010x\n",
OPENSSL_VERSION_NUMBER);
printf("Require OPENSSL_VERSION_NUMBER 0x009070cf or greater (0.9.7l)\n"
- "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n\n");
+ "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n"
+ "Require OPENSSL_VERSION_NUMBER 0x1000000f or greater (1.0.0)\n"
+ "Require OPENSSL_VERSION_NUMBER 0x1000100f or greater (1.0.1)\n"
+ "Require OPENSSL_VERSION_NUMBER 0x1000205f or greater (1.0.2e)\n\n");
return (1);
}
],
WARNING one or more of the the following known security WARNING
WARNING flaws: WARNING
WARNING WARNING
-WARNING CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and WARNING
-WARNING CVE-2006-2940. WARNING
+WARNING CAN-2002-0659, CAN-2006-4339, CVE-2006-2937, WARNING
+WARNING CVE-2006-2940 and CVE-2015-3193. WARNING
WARNING WARNING
WARNING It is recommended that you upgrade to OpenSSL WARNING
-WARNING version 0.9.8d/0.9.7l (or greater). WARNING
+WARNING version 1.0.2e/1.0.1/1.0.0/0.9.9/0.9.8d/0.9.7l WARNING
+WARNING (or greater). WARNING
WARNING WARNING
WARNING You can disable this warning by specifying: WARNING
WARNING WARNING
-WARNING --disable-openssl-version-check WARNING
+WARNING --disable-openssl-version-check WARNING
WARNING WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING