Browse Source

openssl: Updated (0.9.8n -> 0.9.8o) SECURITY! CVE-2010-1633

[IMPORTANT]

An invalid Return value check in pkey_rsa_verifyrecover was discovered. When
verification recovery fails for RSA keys an uninitialised buffer with an
undefined length is returned instead of an error code. This could lead to an
information leak.

original advisory: http://www.openssl.org/news/secadv_20100601.txt
CVE-2010-1633: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1633
user/karasz/test/ecn
Christian Wiese 15 years ago committed by Christian Wiese
parent
commit
b347aefe83
  1. 4
      security/openssl/openssl.desc

4
security/openssl/openssl.desc

@ -35,7 +35,7 @@
[L] OpenSource
[S] Stable
[V] 0.9.8n
[V] 0.9.8o
[P] X -?---5---9 104.600
[D] 4230078551 openssl-0.9.8n.tar.gz http://openssl.org/source/
[D] 3867795964 openssl-0.9.8o.tar.gz http://openssl.org/source/

Loading…
Cancel
Save