[Pkg-openssl-devel] Bug#675436: OpenSSL Buffer Overflow Vulnerability

Henri Salo henri at nerv.fi
Wed Jun 5 11:27:14 UTC 2013


On Sun, Mar 10, 2013 at 12:33:55PM -0400, vin Buccigrossi wrote:
> It has no CVE number but I will package up all of the file and every thing
> we used in testing and send it over to you.

Hello Buccigrossi,

I'm still waiting for the examples and use cases (test files) for this OpenSSL
buffer overflow security vulnerability. I have reported this issue to Debian
project bug tracking system in here http://bugs.debian.org/675436 and I really
would like to get that issue handled properly and then closed.

Particularly my interest is in Debian wheezy release packages. Have you checked
if Debian OpenSSL packages are actually affected by this issue?

---
Henri Salo



More information about the Pkg-openssl-devel mailing list