Matt Caswell matt at openssl.org
Mon Mar 16 19:05:31 UTC 2015
The OpenSSL project team would like to announce the forthcoming release
of OpenSSL versions 1.0.2a, 1.0.1m, 1.0.0r and 0.9.8zf.
These releases will be made available on 19th March. They will fix a
number of security defects. The highest severity defect fixed by these
releases is classified as "high" severity.
20. Mar192015OpenSSLUpdate
? FREAKにvするアップデ`ト
? 0.9.8狼、SSLv3をデフォルトでo浸。1.0.x狼、竃グレ`ドの圧催晒をデフォルトでo浸。
? https://security-tracker.debian.org/tracker/CVE-2015-0209
? https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1b4a8df38fc9ab3c089ca5765075ee53ec5bd66a
? failure to NULL a pointer freed on error.
? https://security-tracker.debian.org/tracker/CVE-2015-0285
? https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=e1b568dd2462f7cacf98f3d117936c34e2849a6b
? under certain conditions a client can complete a handshake with an unseeded PRNG.
? https://security-tracker.debian.org/tracker/CVE-2015-0288
? https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=28a00bcd8e318da18031b2ac8778c64147cd54f9
? crypto/x509/x509_req.c bug #0day
? https://security-tracker.debian.org/tracker/CVE-2015-0291
? 1.0.2 server DoS
? まだ秤鵑竃てないので棋ちましょう。
Copyright ? 1997-2015 CLARA ONLINE,Inc. a limited company incorporated under the Japanese Law, All rights reserved. Reproduction of this publication in any form without prior written permission is forbidden. The information contained herein has been obtained from sources believed to be reliable. Clara Online disclaims all warranties as to the accuracy, completeness or adequacy of
such information. Clara Online shall have no liability for errors, omissions or inadequacies in the information contained herein or for interpretations thereof. The reader assumes sole responsibility for the selection of these materials to achieve its intended results. Clara Online, the "Clara" logo and design is registered trademarks or trademarks of Clara Online, Inc. in the Japan, China and/or
other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Specifications subject to change without notice.