]> code.ossystems Code Review - openembedded-core.git/commit
openssl: backport fix for CVE-2014-0160
authorPaul Eggleton <paul.eggleton@linux.intel.com>
Tue, 8 Apr 2014 18:37:40 +0000 (19:37 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 9 Apr 2014 07:59:00 +0000 (08:59 +0100)
commitbebed954e8fea9d805a0eb6b284dd90177379242
tree53dd25cbf0e594292be0a48e63395b28750a8c51
parent0d3d2d7062a181e878435487c06e26c6547e492f
openssl: backport fix for CVE-2014-0160

Fixes the "heartbleed" TLS vulnerability (CVE-2014-0160). More
information here:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160

Patch borrowed from Debian; this is just a tweaked version of the
upstream commit (without patching the CHANGES file which otherwise
would fail to apply on top of this version).

Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-connectivity/openssl/openssl-1.0.1e/CVE-2014-0160.patch [new file with mode: 0644]
meta/recipes-connectivity/openssl/openssl_1.0.1e.bb