[Secure-testing-commits] r38738 - data/CVE

Paul Wise pabs at moszumanska.debian.org
Thu Jan 7 02:10:14 UTC 2016


Author: pabs
Date: 2016-01-07 02:10:13 +0000 (Thu, 07 Jan 2016)
New Revision: 38738

Modified:
   data/CVE/list
Log:
Update information for openssl & CVE-2015-7575.

Suggested-by: Q_ on #debian-security

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-01-06 21:10:15 UTC (rev 38737)
+++ data/CVE/list	2016-01-07 02:10:13 UTC (rev 38738)
@@ -6711,8 +6711,12 @@
 	- iceweasel 43.0.2-1
 	[squeeze] - iceweasel <end-of-life>
 	- nss 2:3.21-1
+	- openssl 1.0.1f-1
+	[wheezy] - openssl <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2015-150/
 	NOTE: Patch in SuSE Bugzilla: https://bugzilla.novell.com/attachment.cgi?id=660286
+	NOTE: http://www.mitls.org/pages/attacks/SLOTH
+	NOTE: OpenSSL fix is 5e1ff664f95ab4c9
 	TODO: check
 CVE-2015-7574
 	RESERVED




More information about the Secure-testing-commits mailing list