]> code.ossystems Code Review - openembedded-core.git/commit
openssl: update 1.0.2e -> 1.0.2f ( CVE-2016-0701 CVE-2015-3197 )
authorAndre McCurdy <armccurdy@gmail.com>
Thu, 28 Jan 2016 20:55:45 +0000 (12:55 -0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Fri, 29 Jan 2016 18:14:57 +0000 (18:14 +0000)
commitb451e3efc79d29c39c85f7da2dc75becf3fdf5a2
tree0f31c0c10e137977205012bab7e45079874fd696
parent107ab45444bfaa2d287bb490f76b44fc827048b5
openssl: update 1.0.2e -> 1.0.2f ( CVE-2016-0701 CVE-2015-3197 )

Major changes between OpenSSL 1.0.2e and OpenSSL 1.0.2f [28 Jan 2016]

  o DH small subgroups (CVE-2016-0701)
  o SSLv2 doesn't block disabled ciphers (CVE-2015-3197)

Updated LICENSE hash due to change in copyright year.

Signed-off-by: Andre McCurdy <armccurdy@gmail.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-connectivity/openssl/openssl_1.0.2f.bb [moved from meta/recipes-connectivity/openssl/openssl_1.0.2e.bb with 91% similarity]