openssl 1.0.2d-0ubuntu1.5 source package in Ubuntu
Changelog
openssl (1.0.2d-0ubuntu1.5) wily-security; urgency=medium
* SECURITY UPDATE: EVP_EncodeUpdate overflow
- debian/patches/CVE-2016-2105.patch: properly check lengths in
crypto/evp/encode.c, add documentation to
doc/crypto/EVP_EncodeInit.pod, doc/crypto/evp.pod.
- CVE-2016-2105
* SECURITY UPDATE: EVP_EncryptUpdate overflow
- debian/patches/CVE-2016-2106.patch: fix overflow in
crypto/evp/evp_enc.c.
- CVE-2016-2106
* SECURITY UPDATE: Padding oracle in AES-NI CBC MAC check
- debian/patches/CVE-2016-2107.patch: check that there are enough
padding characters in crypto/evp/e_aes_cbc_hmac_sha1.c,
crypto/evp/e_aes_cbc_hmac_sha256.c.
- CVE-2016-2107
* SECURITY UPDATE: Memory corruption in the ASN.1 encoder
- debian/patches/CVE-2016-2108.patch: fix ASN1_INTEGER handling in
crypto/asn1/a_type.c, crypto/asn1/asn1.h, crypto/asn1/tasn_dec.c,
crypto/asn1/tasn_enc.c.
- CVE-2016-2108
* SECURITY UPDATE: ASN.1 BIO excessive memory allocation
- debian/patches/CVE-2016-2109.patch: properly handle large amounts of
data in crypto/asn1/a_d2i_fp.c.
- CVE-2016-2109
* debian/patches/min_1024_dh_size.patch: change minimum DH size from 768
to 1024.
-- Marc Deslauriers <email address hidden> Thu, 28 Apr 2016 10:00:31 -0400
Upload details
- Uploaded by:
- Marc Deslauriers
- Uploaded to:
- Wily
- Original maintainer:
- Ubuntu Developers
- Architectures:
- any all
- Section:
- utils
- Urgency:
- Medium Urgency
See full publishing history Publishing
| Series | Published | Component | Section |
|---|
Downloads
| File | Size | SHA-256 Checksum |
|---|---|---|
| openssl_1.0.2d.orig.tar.gz | 5.1 MiB | 671c36487785628a703374c652ad2cebea45fa920ae5681515df25d9f2c9a8c8 |
| openssl_1.0.2d-0ubuntu1.5.debian.tar.xz | 115.3 KiB | 290fea4afa45f1482027da2961ebfca592fbd98e56789e8b9063fad4578b363b |
| openssl_1.0.2d-0ubuntu1.5.dsc | 2.4 KiB | 5e02f30c956625a307ee96ab4ef15f3ce9ee17c62474495f098a1677aa747182 |
Available diffs
Binary packages built by this source
- libcrypto1.0.0-udeb: No summary available for libcrypto1.0.0-udeb in ubuntu wily.
No description available for libcrypto1.0.0-udeb in ubuntu wily.
- libcrypto1.0.0-udeb-dbgsym: No summary available for libcrypto1.0.0-udeb-dbgsym in ubuntu wily.
No description available for libcrypto1.
0.0-udeb- dbgsym in ubuntu wily.
- libssl-dev: No summary available for libssl-dev in ubuntu wily.
No description available for libssl-dev in ubuntu wily.
- libssl-dev-dbgsym: No summary available for libssl-dev-dbgsym in ubuntu wily.
No description available for libssl-dev-dbgsym in ubuntu wily.
- libssl-doc: No summary available for libssl-doc in ubuntu wily.
No description available for libssl-doc in ubuntu wily.
- libssl1.0.0: No summary available for libssl1.0.0 in ubuntu wily.
No description available for libssl1.0.0 in ubuntu wily.
- libssl1.0.0-dbg: No summary available for libssl1.0.0-dbg in ubuntu wily.
No description available for libssl1.0.0-dbg in ubuntu wily.
- libssl1.0.0-dbgsym: No summary available for libssl1.0.0-dbgsym in ubuntu wily.
No description available for libssl1.0.0-dbgsym in ubuntu wily.
- libssl1.0.0-udeb: No summary available for libssl1.0.0-udeb in ubuntu wily.
No description available for libssl1.0.0-udeb in ubuntu wily.
- libssl1.0.0-udeb-dbgsym: No summary available for libssl1.0.0-udeb-dbgsym in ubuntu wily.
No description available for libssl1.
0.0-udeb- dbgsym in ubuntu wily.
- openssl: No summary available for openssl in ubuntu wily.
No description available for openssl in ubuntu wily.
- openssl-dbgsym: No summary available for openssl-dbgsym in ubuntu wily.
No description available for openssl-dbgsym in ubuntu wily.
