[Pkg-openssl-devel] Issue in OpenSSL

Sebastian Andrzej Siewior sebastian at breakpoint.cc
Fri Feb 5 20:15:22 GMT 2021


On 2021-02-03 13:06:54 [+0100], Armin Fuerst wrote:
> Dear maintainers of OpenSSL,
> 
> I recently found an error in OpenSSL
> (https://github.com/openssl/openssl/issues/13944) which leads to
> expiration of certificates which should not expire yet.
> I also fixed the bug and the fix was merged into openssl (1.1.1-branch
> and master, https://github.com/openssl/openssl/pull/14026).
> I know this is not a major security issue, but is there maybe a chance
> to patch the current buster-package? Since the original code is
> identical in 1.1.1d and 1.1.1i (which was the version I used for fixing
> it), the patch should be simple.

There is a point release this weekend. I hope that after that pu the i
release gets into stable.
Since that bugfix is already in the 1.1.1 branch I would suggest that we
wait for the j release and then try to get this in stable. Would that
work for you?

> Cheers,
> Armin
> 

Sebastian



More information about the Pkg-openssl-devel mailing list