]> code.ossystems Code Review - openembedded-core.git/commit
Security Advisory - openssl - CVE-2013-4353
authorYue Tao <Yue.Tao@windriver.com>
Wed, 26 Mar 2014 09:08:43 +0000 (17:08 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 26 Mar 2014 12:15:11 +0000 (12:15 +0000)
commit35ccce7002188c8270d2fead35f9763b22776877
tree7a21b127c683f24fb216c059316cf9bdc9aa8926
parentf0e1c22ee1cc581fbe8a56e707dcdb015d58fdb6
Security Advisory - openssl - CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before
1.0.1f allows remote TLS servers to cause a denial of service (NULL
pointer dereference and application crash) via a crafted Next Protocol
Negotiation record in a TLS handshake.

Signed-off-by: Yue Tao <Yue.Tao@windriver.com>
Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-connectivity/openssl/openssl-1.0.1e/0001-Fix-for-TLS-record-tampering-bug-CVE-2013-4353.patch [new file with mode: 0644]
meta/recipes-connectivity/openssl/openssl_1.0.1e.bb