-
Committer:
Package Import Robot
-
Author(s):
Marc Deslauriers
-
Date:
2014-05-02 15:18:26 UTC
-
Revision ID:
package-import@ubuntu.com-20140502151826-vomxea77s26g5xou
Tags: 1.0.1f-1ubuntu3
* SECURITY UPDATE: denial of service via use after free
- debian/patches/CVE-2010-5298.patch: check s->s3->rbuf.left before
releasing buffers in ssl/s3_pkt.c.
- CVE-2010-5298
* SECURITY UPDATE: denial of service via null pointer dereference
- debian/patches/CVE-2014-0198.patch: if buffer was released, get a new
one in ssl/s3_pkt.c.
- CVE-2014-0198