Univention Bugzilla – Full Text Bug Listing |
Summary: | openssl: Multiple issues (3.2) | ||
---|---|---|---|
Product: | UCS | Reporter: | Moritz Muehlenhoff <jmm> |
Component: | Security updates | Assignee: | Janek Walkenhorst <walkenhorst> |
Status: | CLOSED FIXED | QA Contact: | Philipp Hahn <hahn> |
Severity: | normal | ||
Priority: | P5 | CC: | gohmann |
Version: | UCS 3.2 | ||
Target Milestone: | UCS 3.2-4-errata | ||
Hardware: | Other | ||
OS: | Linux | ||
What kind of report is it?: | --- | What type of bug is this?: | --- |
Who will be affected by this bug?: | --- | How will those affected feel about the bug?: | --- |
User Pain: | Enterprise Customer affected?: | ||
School Customer affected?: | ISV affected?: | ||
Waiting Support: | Flags outvoted (downgraded) after PO Review: | ||
Ticket number: | Bug group (optional): | ||
Max CVSS v3 score: |
Description
Moritz Muehlenhoff
2014-10-15 10:39:27 CEST
Additional issues have been reported/fixed: Denial of service through memory leak in session ticket validation (CVE-2014-3567) A a mechanism to counter downgrade attacks to SSL3 (TLS_FALLBACK_SCSV) (CVE-2014-3566) The build option no-ssl3 didn't work as expected (CVE-2014-3568) squeeze-lts imported. Tests (amd64): OK Advisory: 2014-12-01-openssl.yaml OK: aptitude install '?source-package(openssl)?installed' OK: amd64 OK: i386 OK: zless /usr/share/doc/openssl/changelog.Debian.gz OK: univention-certificate new -name foo OK: openssl verify -CAfile ucsCA/CAcert.pem -purpose any foo/cert.pem OK: univention-ldapsearch -ZZ OK: (printf 'GET / HTTP/1.1\r\nHost: www.univention.de\r\n\r\n';sleep 1)|openssl s_client -host www.univention.de -port 443 FIXED: 2014-12-01-openssl.yaml r56923 | Bug #36170 OpenSSL: YAML fixes OK: errata-announce --validate-bugzilla -V 2014-12-01-openssl.yaml |