Hello community, here is the log from the commit of package openssl for openSUSE:12.3 checked in at 2013-02-07 10:44:07 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:12.3/openssl (Old) and /work/SRC/openSUSE:12.3/.openssl.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openssl", Maintainer is "g...@suse.com" Changes: -------- --- /work/SRC/openSUSE:12.3/openssl/openssl.changes 2013-01-31 01:29:04.000000000 +0100 +++ /work/SRC/openSUSE:12.3/.openssl.new/openssl.changes 2013-02-07 10:44:09.000000000 +0100 @@ -1,0 +2,11 @@ +Tue Feb 5 16:00:17 UTC 2013 - meiss...@suse.com + +- update to version 1.0.1d, fixing security issues + o Fix renegotiation in TLS 1.1, 1.2 by using the correct TLS version. + o Include the fips configuration module. + o Fix OCSP bad key DoS attack CVE-2013-0166 + o Fix for SSL/TLS/DTLS CBC plaintext recovery attack CVE-2013-0169 + bnc#802184 + o Fix for TLS AESNI record handling flaw CVE-2012-2686 + +------------------------------------------------------------------- Old: ---- openssl-1.0.1c.tar.gz New: ---- openssl-1.0.1d.tar.gz openssl-1.0.1d.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openssl.spec ++++++ --- /var/tmp/diff_new_pack.vZb8aT/_old 2013-02-07 10:44:10.000000000 +0100 +++ /var/tmp/diff_new_pack.vZb8aT/_new 2013-02-07 10:44:10.000000000 +0100 @@ -1,7 +1,7 @@ # # spec file for package openssl # -# Copyright (c) 2012 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2013 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -16,7 +16,6 @@ # - Name: openssl BuildRequires: bc BuildRequires: ed @@ -30,13 +29,14 @@ %ifarch ppc64 Obsoletes: openssl-64bit %endif -Version: 1.0.1c +Version: 1.0.1d Release: 0 Summary: Secure Sockets and Transport Layer Security License: OpenSSL Group: Productivity/Networking/Security Url: http://www.openssl.org/ Source: http://www.%{name}.org/source/%{name}-%{version}.tar.gz +Source42: http://www.%{name}.org/source/%{name}-%{version}.tar.gz.asc # to get mtime of file: Source1: openssl.changes Source2: baselibs.conf ++++++ openssl-1.0.1c.tar.gz -> openssl-1.0.1d.tar.gz ++++++ ++++ 7948 lines of diff (skipped) -- To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org For additional commands, e-mail: opensuse-commit+h...@opensuse.org