From: <abe...@us...> - 2016-03-01 16:26:48
|
Revision: 7567 http://sourceforge.net/p/astlinux/code/7567 Author: abelbeck Date: 2016-03-01 16:26:47 +0000 (Tue, 01 Mar 2016) Log Message: ----------- openssl, version bump to 1.0.1s, removes SSLv2 support, security fixes: CVE-2016-0800 - Cross-protocol attack on TLS using SSLv2 (DROWN) CVE-2016-0705 - Double-free in DSA code CVE-2016-0798 - Memory leak in SRP database lookups CVE-2016-0797 - BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption CVE-2016-0799 - Fix memory issues in BIO_*printf functions CVE-2016-0702 - Side channel attack on modular exponentiation Modified Paths: -------------- branches/1.0/package/openssl/openssl.mk Modified: branches/1.0/package/openssl/openssl.mk =================================================================== --- branches/1.0/package/openssl/openssl.mk 2016-02-28 23:35:53 UTC (rev 7566) +++ branches/1.0/package/openssl/openssl.mk 2016-03-01 16:26:47 UTC (rev 7567) @@ -4,7 +4,7 @@ # ############################################################# -OPENSSL_VERSION = 1.0.1r +OPENSSL_VERSION = 1.0.1s OPENSSL_SITE = http://www.openssl.org/source OPENSSL_INSTALL_STAGING = YES OPENSSL_DEPENDENCIES = zlib This was sent by the SourceForge.net collaborative development platform, the world's largest Open Source development site. |