~ubuntu-branches/ubuntu/quantal/openssl/quantal-security

Viewing all changes in revision 91.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2014-04-07 15:44:36 UTC
  • Revision ID: package-import@ubuntu.com-20140407154436-rnxgy4izv16plabi
Tags: 1.0.1c-3ubuntu2.7
* SECURITY UPDATE: side-channel attack on Montgomery ladder implementation
  - debian/patches/CVE-2014-0076.patch: add and use constant time swap in
    crypto/bn/bn.h, crypto/bn/bn_lib.c, crypto/ec/ec2_mult.c,
    util/libeay.num.
  - CVE-2014-0076
* SECURITY UPDATE: memory disclosure in TLS heartbeat extension
  - debian/patches/CVE-2014-0160.patch: use correct lengths in
    ssl/d1_both.c, ssl/t1_lib.c.
  - CVE-2014-0160

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: