Dear OpenSSL follower,

barsnick just announced version 1.0.1d of OpenSSL on Freecode.

The release notes for this version are as follows:

A weakness in the handling of CBC ciphersuites in SSL, TLS, and DTLS, exploited
through timing differences arising during MAC processing, was fixed. This
vulnerability was reported as CVE-2013-0169. A flaw in the handling of CBC
ciphersuites in TLS 1.1 and TLS 1.2 on AES-NI supporting platforms was fixed.
This vulnerability was reported as CVE-2012-2686. A flaw in the handling of OCSP
response verification, exploitable with a denial of service attack, was fixed.
This vulnerability was reported as CVE-2013-0166.

Project description:

The OpenSSL Project is a collaborative effort to
develop a robust, commercial-grade, fully
featured, and Open Source toolkit implementing the
Secure Sockets Layer (SSL v2/v3) and Transport
Layer Security (TLS v1) as well as a full-strength
general-purpose cryptography library.

Detailed history and release notes are available here:

    http://freecode.com/projects/openssl#release_352038

If you want to unfollow this project, please log in to:

    http://freecode.com/account/subscriptions

Best regards,
Freecode

-- 
This email was sent to [email protected].

Geeknet, Inc. | 594 Howard Street, Suite 300 | San Francisco, CA  94105 
Privacy Policy: http://geek.net/privacy-statement
-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-book
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page

Reply via email to