~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
PublicDateAtUSN: 2016-03-01 13:00:00 UTC
Candidate: CVE-2016-0798
CRD: 2016-03-01 13:00:00 UTC
PublicDate: 2016-03-03
References: 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0798
 https://www.openssl.org/news/secadv/20160301.txt
 http://www.ubuntu.com/usn/usn-2914-1
Description:
 Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1
 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a
 denial of service (memory consumption) by providing an invalid username in
 a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.
Ubuntu-Description: 
Notes: 
Bugs: 
Priority: low
Discovered-by: Emilia Käsper
Assigned-to: mdeslaur

Patches_openssl:
 upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=59a908f1e8380412a81392c468b83bf6071beb2a (1.0.1)
 upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=259b664f950c2ba66fbf4b0fe5281327904ead21 (1.0.2)
upstream_openssl: needs-triage
precise_openssl: released (1.0.1-4ubuntu5.35)
trusty_openssl: released (1.0.1f-1ubuntu2.18)
vivid/ubuntu-core_openssl: released (1.0.1f-1ubuntu11.6)
vivid/stable-phone-overlay_openssl: released (1.0.1f-1ubuntu11.6)
wily_openssl: released (1.0.2d-0ubuntu1.4)
xenial_openssl: released (1.0.2g-1ubuntu2)
devel_openssl: released (1.0.2g-1ubuntu2)

Patches_openssl098:
upstream_openssl098: needs-triage
precise_openssl098: not-affected (code not present)
trusty_openssl098: not-affected (code not present)
vivid/ubuntu-core_openssl098: DNE
vivid/stable-phone-overlay_openssl098: DNE
wily_openssl098: DNE
xenial_openssl098: DNE
devel_openssl098: DNE