[OE-core] [PATCH 0/2][jethro] Jethro-next openssl security fixes

Armin Kuster akuster808 at gmail.com
Fri Jan 29 22:57:06 UTC 2016


please consider these two openssl security issues for the next jethro update

The following changes since commit d2afba471039f94cf251f40298a51dbd640d4e93:

  qemu: Security fix CVE-2015-7295 (2016-01-29 12:31:19 -0800)

are available in the git repository at:

  git://git.yoctoproject.org/poky-contrib akuster/jethro_qemu_sec
  http://git.yoctoproject.org/cgit.cgi/poky-contrib/log/?h=akuster/jethro_qemu_sec

Armin Kuster (2):
  openssl: Security fix CVE-2015-3197
  openssl: Security fix CVE-2016-0701

 .../openssl/openssl/CVE-2015-3197.patch            |  63 +++++++++
 .../openssl/openssl/CVE-2016-0701_1.patch          | 102 ++++++++++++++
 .../openssl/openssl/CVE-2016-0701_2.patch          | 156 +++++++++++++++++++++
 .../recipes-connectivity/openssl/openssl_1.0.2d.bb |   3 +
 4 files changed, 324 insertions(+)
 create mode 100644 meta/recipes-connectivity/openssl/openssl/CVE-2015-3197.patch
 create mode 100644 meta/recipes-connectivity/openssl/openssl/CVE-2016-0701_1.patch
 create mode 100644 meta/recipes-connectivity/openssl/openssl/CVE-2016-0701_2.patch

-- 
2.3.5




More information about the Openembedded-core mailing list