]> code.ossystems Code Review - openembedded-core.git/commit
openssl: CVE-2015-3194, CVE-2015-3195
authorSona Sarmadi <sona.sarmadi@enea.com>
Tue, 15 Dec 2015 10:07:48 +0000 (11:07 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Sat, 30 Jan 2016 12:02:01 +0000 (12:02 +0000)
commit09c3a0f01572a6a65e9f87ce16817ee7de3296f1
tree564f2e15830cb53b5e627bbd790d60b46d71e668
parente40cae30575a227bb0274869f720dffd816d629a
openssl: CVE-2015-3194, CVE-2015-3195

Fixes following vulnerabilities:
Certificate verify crash with missing PSS parameter (CVE-2015-3194)
X509_ATTRIBUTE memory leak (CVE-2015-3195)

References:
https://openssl.org/news/secadv/20151203.txt
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3194
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3195

Upstream patches:
CVE-2015-3194:
https://git.openssl.org/?p=openssl.git;a=commit;h=
d8541d7e9e63bf5f343af24644046c8d96498c17

CVE-2015-3195:
https://git.openssl.org/?p=openssl.git;a=commit;h=
b29ffa392e839d05171206523e84909146f7a77c

Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
meta/recipes-connectivity/openssl/openssl/CVE-2015-3194-Add-PSS-parameter-check.patch [new file with mode: 0644]
meta/recipes-connectivity/openssl/openssl/CVE-2015-3195-Fix-leak-with-ASN.1-combine.patch [new file with mode: 0644]
meta/recipes-connectivity/openssl/openssl_1.0.1p.bb