Bug#740802: stunnel4: CVE-2014-0016

2014-03-06 Thread Salvatore Bonaccorso
Hi Peter, Moritz, all, On Thu, Mar 06, 2014 at 05:41:54PM +0200, Peter Pentchev wrote: > package stunnel4 > owner 740802 ! > tag 740802 + pending > kthxbye > > Hi, > > Thanks for reporting this! I saw it independently in Michal Trojnara's > announcement of stunnel-5.00, but it's good to have it

Bug#740802: [Secure-testing-team] Bug#740802: stunnel4: CVE-2014-0016

2014-03-06 Thread micah
Moritz Muehlenhoff writes: > Package: stunnel4 > Severity: grave > Tags: security > Justification: user security hole > > Hi, > please see http://article.gmane.org/gmane.comp.security.oss.general/12283 According to that post: Mitigations implemented into openssl-0.9.8j (2009) makes the vulnerab

Bug#740802: stunnel4: CVE-2014-0016

2014-03-06 Thread Peter Pentchev
package stunnel4 owner 740802 ! tag 740802 + pending kthxbye Hi, Thanks for reporting this! I saw it independently in Michal Trojnara's announcement of stunnel-5.00, but it's good to have it in the BTS, too. I've backported the fix from stunnel-5.00 to the Git repository of the Debian package o

Bug#740802: stunnel4: CVE-2014-0016

2014-03-04 Thread Moritz Muehlenhoff
Package: stunnel4 Severity: grave Tags: security Justification: user security hole Hi, please see http://article.gmane.org/gmane.comp.security.oss.general/12283 Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble