Summary: | OpenSSL "CRYPTO_free_all_ex_data()" Memory Leak Vulnerability | ||
---|---|---|---|
Product: | Sisyphus | Reporter: | Motsyo Gennadi <drool> |
Component: | openssl | Assignee: | Gleb F-Malinovskiy <glebfm> |
Status: | CLOSED FIXED | QA Contact: | qa-sisyphus |
Severity: | critical | ||
Priority: | P3 | CC: | glebfm |
Version: | unstable | Keywords: | security |
Hardware: | all | ||
OS: | Linux | ||
Bug Depends on: | 23037 | ||
Bug Blocks: |
Description
Motsyo Gennadi
2010-01-24 18:18:48 MSK
Будем чинить... openssl-0.9.8m-beta1, заодно, посмотрю... openssl098-0.9.8o-alt1 -> sisyphus: * Wed Sep 29 2010 Dmitry V. Levin <ldv@altlinux> 0.9.8o-alt1 - Updated to 0.9.8o (fixes CVE-2010-0742). - Fixed ssl/dtls1.h ABI breakage introduced in 0.9.8m. - Fixed 0.9.8m build regression on architectures where %_lib != lib. * Thu Mar 25 2010 Evgeny Sinelnikov <sin@altlinux> 0.9.8n-alt1 - Updated to 0.9.8n (fixes CVE-2010-0740 and CVE-2010-0433). * Fri Feb 26 2010 Evgeny Sinelnikov <sin@altlinux> 0.9.8m-alt1 - Updated to 0.9.8m with security fixes and improvements, including: + CVE-2009-3245, CVE-2008-1678 + CVE-2009-1377, CVE-2009-1378, CVE-2009-1379 + CVE-2009-1387 (closes: #20280) + CVE-2009-4355 (closes: #22817, #23037) + patch for Cisco VPN client DTLS |