[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

openssl security update

Package: openssl
Version: 0.9.8o-4squeeze16
CVE ID: CVE-2014-0224 CVE-2012-4929


    This update updates the upstream fix for CVE-2014-0224 to address
    problems with renegotiation under some conditions.

    original text:
    KIKUCHI Masashi discovered that carefully crafted handshakes can
    force the use of weak keys, resulting in potential man-in-the-middle


    ZLIB compression is now disabled by default.  If you need
    to re-enable it for some reason, you can set the environment

It's important that you upgrade the libssl0.9.8 package and not
just the openssl package.

All applications linked to openssl need to be restarted. You can
use the tool checkrestart from the package debian-goodies to
detect affected programs or reboot your system.


Attachment: signature.asc
Description: Digital signature

Reply to: