On Mon, Jan 06, 2014 at 07:53:41PM +0100, Moritz Mühlenhoff wrote:
> > > >
> > > > So after uploading this, I got this as reply:
> > > > > Although there is no CVE connected to it it is also advisable to
> > > > > include f3dcc8411e518fb0835c7d72df4a58718205260d as well.
> > > >
> > > > Should I
On Mon, Jan 06, 2014 at 07:41:05PM +0100, Kurt Roeckx wrote:
> On Mon, Jan 06, 2014 at 07:35:40PM +0100, Moritz Mühlenhoff wrote:
> > On Mon, Jan 06, 2014 at 07:20:25PM +0100, Kurt Roeckx wrote:
> > > On Mon, Jan 06, 2014 at 06:54:33PM +0100, Kurt Roeckx wrote:
> > > > On Mon, Jan 06, 2014 at 06:24
On Mon, Jan 06, 2014 at 07:35:40PM +0100, Moritz Mühlenhoff wrote:
> On Mon, Jan 06, 2014 at 07:20:25PM +0100, Kurt Roeckx wrote:
> > On Mon, Jan 06, 2014 at 06:54:33PM +0100, Kurt Roeckx wrote:
> > > On Mon, Jan 06, 2014 at 06:24:14PM +0100, Kurt Roeckx wrote:
> > > > On Mon, Dec 23, 2013 at 06:44
On Mon, Jan 06, 2014 at 07:20:25PM +0100, Kurt Roeckx wrote:
> On Mon, Jan 06, 2014 at 06:54:33PM +0100, Kurt Roeckx wrote:
> > On Mon, Jan 06, 2014 at 06:24:14PM +0100, Kurt Roeckx wrote:
> > > On Mon, Dec 23, 2013 at 06:44:23PM +0100, Kurt Roeckx wrote:
> > > > On Sun, Dec 22, 2013 at 11:51:09PM
On Mon, Jan 06, 2014 at 06:54:33PM +0100, Kurt Roeckx wrote:
> On Mon, Jan 06, 2014 at 06:24:14PM +0100, Kurt Roeckx wrote:
> > On Mon, Dec 23, 2013 at 06:44:23PM +0100, Kurt Roeckx wrote:
> > > On Sun, Dec 22, 2013 at 11:51:09PM +0100, Kurt Roeckx wrote:
> > > >
> > > > For security I would like
On Mon, Jan 06, 2014 at 06:24:14PM +0100, Kurt Roeckx wrote:
> On Mon, Dec 23, 2013 at 06:44:23PM +0100, Kurt Roeckx wrote:
> > On Sun, Dec 22, 2013 at 11:51:09PM +0100, Kurt Roeckx wrote:
> > >
> > > For security I would like to have the following:
> > > - CVE-2013-6449: 0294b2be5f4c11e60620c0018
On Mon, Dec 23, 2013 at 06:44:23PM +0100, Kurt Roeckx wrote:
> On Sun, Dec 22, 2013 at 11:51:09PM +0100, Kurt Roeckx wrote:
> >
> > For security I would like to have the following:
> > - CVE-2013-6449: 0294b2be5f4c11e60620c0018674ff0e17b14238 +
> > ca989269a2876bae79393bd54c3e72d49975fc75
> > -
On Mon, Dec 23, 2013 at 06:44:23PM +0100, Kurt Roeckx wrote:
> On Sun, Dec 22, 2013 at 11:51:09PM +0100, Kurt Roeckx wrote:
> >
> > For security I would like to have the following:
> > - CVE-2013-6449: 0294b2be5f4c11e60620c0018674ff0e17b14238 +
> > ca989269a2876bae79393bd54c3e72d49975fc75
> > -
On Sun, Dec 22, 2013 at 11:51:09PM +0100, Kurt Roeckx wrote:
>
> For security I would like to have the following:
> - CVE-2013-6449: 0294b2be5f4c11e60620c0018674ff0e17b14238 +
> ca989269a2876bae79393bd54c3e72d49975fc75
> - CVE-2013-6450: 34628967f1e65dc8f34e000f0f5518e21afbfc7b
> - disable rdra
On Sun, Dec 22, 2013 at 07:14:00PM +0100, Kurt Roeckx wrote:
> On Sun, Dec 22, 2013 at 12:25:16AM +0100, Kurt Roeckx wrote:
> > But I'm also thinking about at least #732710
> >
> > There are also things like:
> > Author: Dr. Stephen Henson
> > Date: Mon Sep 16 05:23:44 2013 +0100
> >
> > D
On Sun, Dec 22, 2013 at 12:25:16AM +0100, Kurt Roeckx wrote:
> But I'm also thinking about at least #732710
>
> There are also things like:
> Author: Dr. Stephen Henson
> Date: Mon Sep 16 05:23:44 2013 +0100
>
> Disable Dual EC DRBG.
>
> Return an error if an attempt is made to enable
On Sat, Dec 21, 2013 at 09:24:38PM +0100, Salvatore Bonaccorso wrote:
> Hi Kurt,
>
> On Sat, Dec 21, 2013 at 09:35:38AM +0100, Kurt Roeckx wrote:
> > On Sat, Dec 21, 2013 at 08:16:42AM +0100, Salvatore Bonaccorso wrote:
> > > Package: openssl
> > > Version: 1.0.1e-2
> > > Severity: grave
> > > Tag
Hi Kurt,
On Sat, Dec 21, 2013 at 09:35:38AM +0100, Kurt Roeckx wrote:
> On Sat, Dec 21, 2013 at 08:16:42AM +0100, Salvatore Bonaccorso wrote:
> > Package: openssl
> > Version: 1.0.1e-2
> > Severity: grave
> > Tags: security upstream patch
> >
> > Hi,
> >
> > the following vulnerability was publi
On Sat, Dec 21, 2013 at 08:16:42AM +0100, Salvatore Bonaccorso wrote:
> Package: openssl
> Version: 1.0.1e-2
> Severity: grave
> Tags: security upstream patch
>
> Hi,
>
> the following vulnerability was published for openssl.
>
> CVE-2013-6449[0]:
> crash when using TLS 1.2
>
> It was reported
Package: openssl
Version: 1.0.1e-2
Severity: grave
Tags: security upstream patch
Hi,
the following vulnerability was published for openssl.
CVE-2013-6449[0]:
crash when using TLS 1.2
It was reported in Apache Traffic Server[1] and upstream at [2], see
also [3]. I was not able to reproduce any c
15 matches
Mail list logo