Path to this page:
Subject: CVS commit: pkgsrc/security/openssl
From: Jonathan Perkin
Date: 2016-09-26 14:27:56
Message id: 20160926122756.15E41FBD2@cvs.NetBSD.org
Log Message:
Update security/openssl to 1.0.2j.
Changes between 1.0.2i and 1.0.2j [26 Sep 2016]
*) Missing CRL sanity check
A bug fix which included a CRL sanity check was added to OpenSSL 1.1.0
but was omitted from OpenSSL 1.0.2i. As a result any attempt to use
CRLs in OpenSSL 1.0.2i will crash with a null pointer exception.
This issue only affects the OpenSSL 1.0.2i
(CVE-2016-7052)
[Matt Caswell]
Files: