[ubuntu/xenial-security] erlang 1:18.3-dfsg-1ubuntu3.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Feb 14 14:45:00 UTC 2018


erlang (1:18.3-dfsg-1ubuntu3.1) xenial-security; urgency=medium

  * SECURITY UPDATE: heap overflow in PCRE
    - debian/patches/CVE-2016-10253.patch: add mutual recursion detection
      to erts/emulator/pcre/pcre_compile.c.
    - CVE-2016-10253
  * SECURITY UPDATE: Adaptive Chosen Ciphertext attack in TLS server
    - debian/patches/CVE-2017-1000385.patch: add countermeasurements for
      Bleichenbacher attack in lib/ssl/src/ssl_connection.erl,
      lib/ssl/src/ssl_connection.hrl, lib/ssl/src/tls_connection.erl.
    - CVE-2017-1000385

Date: 2017-12-07 17:03:18.404459+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list