Skip to content
  • Timo Teräs's avatar
    main/openssl: security upgrade to 1.0.1k · 79754059
    Timo Teräs authored and Natanael Copa's avatar Natanael Copa committed
    fixes #3687
    
    CVE-2014-3571 DTLS segmentation fault in dtls1_get_record
    CVE-2015-0206 DTLS memory leak in dtls1_buffer_record
    CVE-2014-3569 no-ssl3 configuration sets method to NULL
    CVE-2014-3572 ECDHE silently downgrades to ECDH [Client]
    CVE-2015-0204 RSA silently downgrades to EXPORT_RSA [Client]
    CVE-2015-0205 DH client certificates accepted without verification [Server]
    CVE-2014-8275 Certificate fingerprints can be modified
    CVE-2014-3570 Bignum squaring may produce incorrect results
    (cherry picked from commit 26dd3845)
    
    Conflicts:
    	main/openssl/APKBUILD
    79754059