• [^] # Re: Debian stable wheezy à jour mais version 1.0.1e

    Posté par . En réponse à la dépêche Nouvelle vulnérabilité dans l’implémentation OpenSSL. Évalué à 7.

    apt-listchanges -a /var/cache/apt/archives/openssl_1.0.1e-2+deb7u6_amd64.deb

    ou

    zless /usr/share/doc/openssl/changelog.Debian.gz

    openssl (1.0.1e-2+deb7u6) wheezy-security; urgency=high

    • Non-maintainer upload by the Security Team.
    • Enable checking for services that may need to be restarted
    • Update list of services to possibly restart

    -- Salvatore Bonaccorso carnil@debian.org 2014年4月08日 10:44:53 +0200

    openssl (1.0.1e-2+deb7u5) wheezy-security; urgency=high

    • Non-maintainer upload by the Security Team.
    • Add CVE-2014-0160.patch patch.
      CVE-2014-0160: Fix TLS/DTLS hearbeat information disclosure.
      A missing bounds check in the handling of the TLS heartbeat extension
      can be used to reveal up to 64k of memory to a connected client or
      server.

    -- Salvatore Bonaccorso carnil@debian.org 2014年4月07日 22:26:55 +0200
    ```

    « Rappelez-vous toujours que si la Gestapo avait les moyens de vous faire parler, les politiciens ont, eux, les moyens de vous faire taire. » Coluche