openssl 1.0.2g-1ubuntu5 source package in Ubuntu

Changelog

openssl (1.0.2g-1ubuntu5) yakkety; urgency=medium

  * SECURITY UPDATE: EVP_EncodeUpdate overflow
    - debian/patches/CVE-2016-2105.patch: properly check lengths in
      crypto/evp/encode.c, add documentation to
      doc/crypto/EVP_EncodeInit.pod, doc/crypto/evp.pod.
    - CVE-2016-2105
  * SECURITY UPDATE: EVP_EncryptUpdate overflow
    - debian/patches/CVE-2016-2106.patch: fix overflow in
      crypto/evp/evp_enc.c.
    - CVE-2016-2106
  * SECURITY UPDATE: Padding oracle in AES-NI CBC MAC check
    - debian/patches/CVE-2016-2107.patch: check that there are enough
      padding characters in crypto/evp/e_aes_cbc_hmac_sha1.c,
      crypto/evp/e_aes_cbc_hmac_sha256.c.
    - CVE-2016-2107
  * SECURITY UPDATE: Memory corruption in the ASN.1 encoder
    - debian/patches/CVE-2016-2108.patch: fix ASN1_INTEGER handling in
      crypto/asn1/a_type.c, crypto/asn1/asn1.h, crypto/asn1/tasn_dec.c,
      crypto/asn1/tasn_enc.c.
    - CVE-2016-2108
  * SECURITY UPDATE: ASN.1 BIO excessive memory allocation
    - debian/patches/CVE-2016-2109.patch: properly handle large amounts of
      data in crypto/asn1/a_d2i_fp.c.
    - CVE-2016-2109

 -- Marc Deslauriers <email address hidden>  Thu, 23 Jun 2016 08:33:31 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Yakkety
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssl_1.0.2g.orig.tar.gz 5.0 MiB b784b1b3907ce39abf4098702dade6365522a253ad1552e267a9a0e89594aa33
openssl_1.0.2g-1ubuntu5.debian.tar.xz 186.0 KiB 756c51a5b5b887d448ddcdaa527082cf705f0f24c7d01329fa1c8d3dbcbd3fb5
openssl_1.0.2g-1ubuntu5.dsc 2.4 KiB de63ea694bcf288dd9546b4fea584f3a19398af3d72f64036d4d4cded797572f

View changes file

Binary packages built by this source

libcrypto1.0.0-udeb: No summary available for libcrypto1.0.0-udeb in ubuntu yakkety.

No description available for libcrypto1.0.0-udeb in ubuntu yakkety.

libcrypto1.0.0-udeb-dbgsym: No summary available for libcrypto1.0.0-udeb-dbgsym in ubuntu yakkety.

No description available for libcrypto1.0.0-udeb-dbgsym in ubuntu yakkety.

libssl-dev: No summary available for libssl-dev in ubuntu yakkety.

No description available for libssl-dev in ubuntu yakkety.

libssl-dev-dbgsym: No summary available for libssl-dev-dbgsym in ubuntu yakkety.

No description available for libssl-dev-dbgsym in ubuntu yakkety.

libssl-doc: No summary available for libssl-doc in ubuntu yakkety.

No description available for libssl-doc in ubuntu yakkety.

libssl1.0.0: No summary available for libssl1.0.0 in ubuntu yakkety.

No description available for libssl1.0.0 in ubuntu yakkety.

libssl1.0.0-dbg: No summary available for libssl1.0.0-dbg in ubuntu yakkety.

No description available for libssl1.0.0-dbg in ubuntu yakkety.

libssl1.0.0-dbgsym: No summary available for libssl1.0.0-dbgsym in ubuntu yakkety.

No description available for libssl1.0.0-dbgsym in ubuntu yakkety.

libssl1.0.0-udeb: No summary available for libssl1.0.0-udeb in ubuntu yakkety.

No description available for libssl1.0.0-udeb in ubuntu yakkety.

libssl1.0.0-udeb-dbgsym: No summary available for libssl1.0.0-udeb-dbgsym in ubuntu yakkety.

No description available for libssl1.0.0-udeb-dbgsym in ubuntu yakkety.

openssl: No summary available for openssl in ubuntu yakkety.

No description available for openssl in ubuntu yakkety.

openssl-dbgsym: No summary available for openssl-dbgsym in ubuntu yakkety.

No description available for openssl-dbgsym in ubuntu yakkety.