[ubuntu/xenial-updates] pyopenssl 0.15.1-2ubuntu0.2 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Thu Nov 8 13:58:08 UTC 2018

pyopenssl (0.15.1-2ubuntu0.2) xenial-security; urgency=medium

  * SECURITY UPDATE: use-after-free and memory leak
    - debian/patches/CVE-2018-100080x-pre.patch: fix use-after-free and
      introduce _from_raw_x509_ptr in OpenSSL/SSL.py, OpenSSL/crypto.py.
    - debian/patches/CVE-2018-100080x.patch: fix issues in OpenSSL/SSL.py,
      OpenSSL/crypto.py, add test to OpenSSL/test/test_ssl.py.
    - debian/control: depend on python-cryptography security update to
      get access to new X509_up_ref function.
    - CVE-2018-1000807
    - CVE-2018-1000808
  * debian/patches/update_certs.patch: update expired test certs.

Date: 2018-11-07 18:59:13.933980+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Xenial-changes mailing list