Re: [OE-core] [PATCH][dizzy] Update openssl to 1.0.1m

2015-03-26 Thread Brendan Le Foll
On Wed, Mar 25, 2015 at 07:32:20AM -0700, akuster808 wrote: On 3/25/15 6:15 AM, brendan.le.f...@intel.com wrote: Thank you for your support on Dizzy. If it isn't too mush trouble, is it possible to get the CVE's list are are being addressed by this update? Here are the CVEs that are

[OE-core] [PATCH][dizzy] Update openssl to 1.0.1m

2015-03-25 Thread brendan . le . foll
From: Brendan Le Foll brendan.le.f...@intel.com Due to recent security fixes it's advisable to update to the latest openssl version. I propose an update to 1.0.1m rather than simply patching the individual CVEs which is much more time consuming/error prone This is exactly the same patch as for

Re: [OE-core] [PATCH][dizzy] Update openssl to 1.0.1m

2015-03-25 Thread akuster808
On 3/25/15 6:15 AM, brendan.le.f...@intel.com wrote: Thank you for your support on Dizzy. If it isn't too mush trouble, is it possible to get the CVE's list are are being addressed by this update? regards, Armin From: Brendan Le Foll brendan.le.f...@intel.com Due to recent security fixes