Bug#603709: [Pkg-openssl-devel] Bug#603709: openssl: CVE-2010-3864

2010-11-19 Thread Kurt Roeckx
On Fri, Nov 19, 2010 at 12:15:45PM +0200, Ivan Zahariev wrote: > Hi Kurt, > > On "16 Nov 2010 18:57:45 +0100" you wrote that you uploaded > "openssl-0.9.8g-15+lenny9" to the security archive, but this package > version is still not available online: > > http://security.debian.org/debian-security/

Bug#603709: [Pkg-openssl-devel] Bug#603709: openssl: CVE-2010-3864

2010-11-19 Thread Ivan Zahariev
Hi Kurt, On "16 Nov 2010 18:57:45 +0100" you wrote that you uploaded "openssl-0.9.8g-15+lenny9" to the security archive, but this package version is still not available online: http://security.debian.org/debian-security/pool/updates/main/o/openssl/ Furthermore, as expected, "apt-get upgrade"

Bug#603709: [Pkg-openssl-devel] Bug#603709: openssl: CVE-2010-3864

2010-11-16 Thread Kurt Roeckx
found 603709 0.9.8g-15 close 603709 0.9.8g-15+lenny9 thanks On Tue, Nov 16, 2010 at 05:26:33PM +, Marcos Marado wrote: > Package: openssl > Version: 0.9.8g-15+lenny8 > Severity: normal > > According to http://www.openssl.org/news/secadv_20101116.txt openssl 0.9.8g > (in > lenny) and and 0.9.

Bug#603709: openssl: CVE-2010-3864

2010-11-16 Thread Marcos Marado
Package: openssl Version: 0.9.8g-15+lenny8 Severity: normal According to http://www.openssl.org/news/secadv_20101116.txt openssl 0.9.8g (in lenny) and and 0.9.8o (in squeeze and sid) are vulnerable to CVE-2010-3864. The link indicates that 0.9.8p fixes this issue, and also includes patches for f