[ubuntu/precise-updates] pyopenssl 0.12-1ubuntu2.1 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Mon Sep 23 18:28:16 UTC 2013
pyopenssl (0.12-1ubuntu2.1) precise-security; urgency=low
* SECURITY UPDATE: incorrect ssl cert validation via NUL byte in
subjectAltName
- debian/patches/CVE-2013-4314.patch: fix leak in OpenSSL/crypto/x509.c,
properly handle subjectAltName in OpenSSL/crypto/x509ext.c, added
tests to OpenSSL/test/test_crypto.py.
- CVE-2013-4314
* debian/patches/remove_sslv2_test.patch: fix test suite failure by
removing SSLv2 in test_method as openssl in precise doesn't enable it.
Date: 2013-09-23 14:42:24.138147+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/precise/+source/pyopenssl/0.12-1ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Precise-changes
mailing list