UbuntuUpdates.org

Package "libssl1.0.0"

Name: libssl1.0.0

Description:

Secure Sockets Layer toolkit - shared libraries

Latest version: 1.0.1f-1ubuntu2
Release: trusty (14.04)
Level: base
Repository: main
Head package: openssl

Links


Download "libssl1.0.0"


Other versions of "libssl1.0.0" in Trusty

Repository Area Version
security main 1.0.1f-1ubuntu2.27
updates main 1.0.1f-1ubuntu2.27

Changelog

Version: 1.0.1f-1ubuntu2 2014-04-08 00:06:57 UTC

  openssl (1.0.1f-1ubuntu2) trusty; urgency=medium

  * SECURITY UPDATE: side-channel attack on Montgomery ladder implementation
    - debian/patches/CVE-2014-0076.patch: add and use constant time swap in
      crypto/bn/bn.h, crypto/bn/bn_lib.c, crypto/ec/ec2_mult.c,
      util/libeay.num.
    - CVE-2014-0076
  * SECURITY UPDATE: memory disclosure in TLS heartbeat extension
    - debian/patches/CVE-2014-0160.patch: use correct lengths in
      ssl/d1_both.c, ssl/t1_lib.c.
    - CVE-2014-0160
 -- Marc Deslauriers <email address hidden> Mon, 07 Apr 2014 15:37:53 -0400

CVE-2014-0076 The Montgomery ladder implementation in OpenSSL through 1.0.0l does ...
CVE-2014-0160 OpenSSL 1.0.1 TLS/DTLS hearbeat information disclosure



About   -   Send Feedback to @ubuntu_updates