~ubuntu-branches/ubuntu/lucid/openssl/lucid-proposed

« back to all changes in this revision

Viewing changes to debian/patches/CVE-2009-2409.patch

  • Committer: Bazaar Package Importer
  • Author(s): Nicolas Valcárcel Scerpella (Canonical)
  • Date: 2009-12-06 20:16:24 UTC
  • mfrom: (11.1.9 sid)
  • Revision ID: james.westby@ubuntu.com-20091206201624-u126qjpqm2n2uuhu
Tags: 0.9.8k-7ubuntu1
* Merge from debian unstable, remaining changes (LP: #493392):
  - Link using -Bsymbolic-functions
  - Add support for lpia
  - Disable SSLv2 during compile
  - Ship documentation in openssl-doc, suggested by the package.
  - Use a different priority for libssl0.9.8/restart-services
    depending on whether a desktop, or server dist-upgrade is being
    performed.
  - Display a system restart required notification bubble on libssl0.9.8
    upgrade.
  - Replace duplicate files in the doc directory with symlinks.
  - Move runtime libraries to /lib, for the benefit of wpasupplicant
* Strip the patches out of the source into quilt patches
* Disable CVE-2009-3555.patch

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
This is http://cvs.openssl.org/chngview?cn=18381
 
2
Fixes CVE-2009-2409
 
3
 
 
4
Index: openssl/crypto/evp/c_alld.c
 
5
RCS File: /v/openssl/cvs/openssl/crypto/evp/c_alld.c,v
 
6
rcsdiff -q -kk '-r1.7' '-r1.7.2.1' -u '/v/openssl/cvs/openssl/crypto/evp/c_alld.c,v' 2>/dev/null
 
7
--- c_alld.c    2005/04/30 21:51:40     1.7
 
8
+++ c_alld.c    2009/07/08 08:33:26     1.7.2.1
 
9
@@ -64,9 +64,6 @@
 
10
 
 
11
 void OpenSSL_add_all_digests(void)
 
12
        {
 
13
-#ifndef OPENSSL_NO_MD2
 
14
-       EVP_add_digest(EVP_md2());
 
15
-#endif
 
16
 #ifndef OPENSSL_NO_MD4
 
17
        EVP_add_digest(EVP_md4());
 
18
 #endif
 
19
Index: openssl/ssl/ssl_algs.c
 
20
RCS File: /v/openssl/cvs/openssl/ssl/ssl_algs.c,v
 
21
rcsdiff -q -kk '-r1.12.2.3' '-r1.12.2.4' -u '/v/openssl/cvs/openssl/ssl/ssl_algs.c,v' 2>/dev/null
 
22
--- ssl_algs.c  2007/04/23 23:50:21     1.12.2.3
 
23
+++ ssl_algs.c  2009/07/08 08:33:27     1.12.2.4
 
24
@@ -92,9 +92,6 @@
 
25
        EVP_add_cipher(EVP_seed_cbc());
 
26
 #endif
 
27
 
 
28
-#ifndef OPENSSL_NO_MD2
 
29
-       EVP_add_digest(EVP_md2());
 
30
-#endif
 
31
 #ifndef OPENSSL_NO_MD5
 
32
        EVP_add_digest(EVP_md5());
 
33
        EVP_add_digest_alias(SN_md5,"ssl2-md5");