openssl update

Michal Jaegermann michal at harddata.com
Wed Mar 17 23:28:09 UTC 2004


On Wed, Mar 17, 2004 at 02:49:32PM -0800, Jesse Keating wrote:
> 
> What makes you think they are?

The code seems to be everywhere really the same and really the same
patches apply.  Also people from Red Hat seem to be of the same
opinion as packages listed in Red Hat alert RHSA-2004:119-01 are,
for all practical purposes, the same as what is used in 7.3.

> The only thing they are effected by is 
> CAN-2004-0081, which is a one line fix.  See 
> http://cvs.openssl.org/chngview?cn=5721 for the fix.

Fixes are indeed really short. openssl-0.9.6c-spinfix.patch is
really a one-liner; openssl-0.9.6b-recursion.patch for ASN1 code
a bit longer but not by much.

   Michal





More information about the fedora-legacy-list mailing list