[OE-core] [master][PATCH] openssl: security fix CVE-2016-6304

Alexander Kanavin alexander.kanavin at linux.intel.com
Mon Sep 26 12:40:33 UTC 2016


On 09/23/2016 06:20 PM, Patrick Ohly wrote:

> The compile error is inside an #ifdef, so it could be that just that
> particular configuration hadn't been tested. But yes, one has to wonder.
>
> So what's preferred for OE-core master and the 2.2 release? Updating to
> 1.0.2i or backporting the critical patch?
>
> I don't have any strong opinion either way myself.

Meanwhile, 1.0.2j is out :) I'd say for master we should just go ahead 
and update to that.

Alex




More information about the Openembedded-core mailing list