Bug#947949: openssl: CVE-2019-1551

2020-01-02 Thread Salvatore Bonaccorso
Hi Sebastian, On Thu, Jan 02, 2020 at 06:10:06PM +, Sebastian Andrzej Siewior wrote: > On January 2, 2020 3:50:46 PM UTC, Salvatore Bonaccorso > wrote: > >If you fix the vulnerability please also make sure to include the > >CVE (Common Vulnerabilities & Exposures) id in your changelog

Bug#947949: openssl: CVE-2019-1551

2020-01-02 Thread Sebastian Andrzej Siewior
On January 2, 2020 3:50:46 PM UTC, Salvatore Bonaccorso wrote: >If you fix the vulnerability please also make sure to include the >CVE (Common Vulnerabilities & Exposures) id in your changelog entry. There is no upstream release which includes this fix (except for the 1.0.2 series). Should we

Bug#947949: openssl: CVE-2019-1551

2020-01-02 Thread Salvatore Bonaccorso
Source: openssl Version: 1.1.1d-2 Severity: important Tags: security upstream fixed-upstream Hi, Filling for tracking the issue for src:openssl. CVE-2019-1551[0]: | There is an overflow bug in the x64_64 Montgomery squaring procedure | used in exponentiation with 512-bit moduli. No EC