Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 23 Jan 2017 02:36:50 +0000 (UTC)
From:      Jason Unovitch <junovitch@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r432189 - head/security/vuxml
Message-ID:  <201701230236.v0N2aoOh063924@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: junovitch
Date: Mon Jan 23 02:36:50 2017
New Revision: 432189
URL: https://svnweb.freebsd.org/changeset/ports/432189

Log:
  Update OpenSSL impacted version
  
  The reference cites 1.0.1u and prior as impacted. security/openssl would
  have resolved in r381789. security/openssl-devel would have not have been
  impacted as that port had been the newer 1.1.x branch since inception.
  
  Reported by:	Thomas Schemme (via email)
  Security:	CVE-2016-7056
  Security:	https://vuxml.FreeBSD.org/freebsd/7caebe30-d7f1-11e6-a9a5-b499baebfeaf.html

Modified:
  head/security/vuxml/vuln.xml

Modified: head/security/vuxml/vuln.xml
==============================================================================
--- head/security/vuxml/vuln.xml	Mon Jan 23 02:35:42 2017	(r432188)
+++ head/security/vuxml/vuln.xml	Mon Jan 23 02:36:50 2017	(r432189)
@@ -674,17 +674,13 @@ Notes:
     <affects>
       <package>
 	<name>openssl</name>
-	<range><lt>1.0.2j_2,1</lt></range>
+	<range><lt>1.0.2</lt></range>
       </package>
       <package>
 	<name>libressl</name>
 	<range><lt>2.4.4_1</lt></range>
       </package>
       <package>
-	<name>openssl-devel</name>
-	<range><lt>1.1.0c_1</lt></range>
-      </package>
-      <package>
 	<name>libressl-devel</name>
 	<range><lt>2.5.0_1</lt></range>
       </package>
@@ -711,6 +707,7 @@ Notes:
     <dates>
       <discovery>2017-01-10</discovery>
       <entry>2017-01-11</entry>
+      <modified>2017-01-11</modified>
     </dates>
   </vuln>
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201701230236.v0N2aoOh063924>