Package "openssl"

Name: openssl


Secure Sockets Layer toolkit - cryptographic utility

Latest version: 1.0.1f-1ubuntu2
Release: trusty (14.04)
Level: base
Repository: main


Download "openssl"

Other versions of "openssl" in Trusty

Repository Area Version
security main 1.0.1f-1ubuntu2.27
updates main 1.0.1f-1ubuntu2.27

Packages in group

Deleted packages are displayed in grey.


Version: 1.0.1f-1ubuntu2 2014-04-08 00:06:57 UTC

  openssl (1.0.1f-1ubuntu2) trusty; urgency=medium

  * SECURITY UPDATE: side-channel attack on Montgomery ladder implementation
    - debian/patches/CVE-2014-0076.patch: add and use constant time swap in
      crypto/bn/bn.h, crypto/bn/bn_lib.c, crypto/ec/ec2_mult.c,
    - CVE-2014-0076
  * SECURITY UPDATE: memory disclosure in TLS heartbeat extension
    - debian/patches/CVE-2014-0160.patch: use correct lengths in
      ssl/d1_both.c, ssl/t1_lib.c.
    - CVE-2014-0160
 -- Marc Deslauriers <email address hidden> Mon, 07 Apr 2014 15:37:53 -0400

CVE-2014-0076 The Montgomery ladder implementation in OpenSSL through 1.0.0l does ...
CVE-2014-0160 OpenSSL 1.0.1 TLS/DTLS hearbeat information disclosure

About   -   Send Feedback to @ubuntu_updates