[ubuntu/xenial-updates] pyopenssl 0.15.1-2ubuntu0.2 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Thu Nov 8 13:58:08 UTC 2018
pyopenssl (0.15.1-2ubuntu0.2) xenial-security; urgency=medium
* SECURITY UPDATE: use-after-free and memory leak
- debian/patches/CVE-2018-100080x-pre.patch: fix use-after-free and
introduce _from_raw_x509_ptr in OpenSSL/SSL.py, OpenSSL/crypto.py.
- debian/patches/CVE-2018-100080x.patch: fix issues in OpenSSL/SSL.py,
OpenSSL/crypto.py, add test to OpenSSL/test/test_ssl.py.
- debian/control: depend on python-cryptography security update to
get access to new X509_up_ref function.
- CVE-2018-1000807
- CVE-2018-1000808
* debian/patches/update_certs.patch: update expired test certs.
Date: 2018-11-07 18:59:13.933980+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/pyopenssl/0.15.1-2ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list