Automatic conversion of the NetBSD pkgsrc CVS module, use with care
Find a file
obache 5be2a0a5f4 Apply following update to suse131_openssl, bump PKGREVISION.
openSUSE Security Update: Security update for openssl
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2015:0130-1
Rating:             important
References:         #911399 #912014 #912015 #912018 #912292 #912293
                    #912294 #912296
Cross-References:   CVE-2014-3569 CVE-2014-3570 CVE-2014-3571
                    CVE-2014-3572 CVE-2014-8275 CVE-2015-0204
                    CVE-2015-0205 CVE-2015-0206
Affected Products:
                    openSUSE 13.2
                    openSUSE 13.1
______________________________________________________________________________

   An update that fixes 8 vulnerabilities is now available.

Description:


   openssl was updated to 1.0.1k to fix various security issues and bugs.

   More information can be found in the openssl advisory:
   http://openssl.org/news/secadv_20150108.txt

   Following issues were fixed:

   * CVE-2014-3570 (bsc#912296): Bignum squaring (BN_sqr) may have produced
     incorrect results on some platforms, including x86_64.

   * CVE-2014-3571 (bsc#912294): Fixed crash in dtls1_get_record whilst in
     the listen state where you get two separate reads performed - one for
     the header and one for the body of the handshake record.

   * CVE-2014-3572 (bsc#912015): Don't accept a handshake using an ephemeral
     ECDH ciphersuites with the server key exchange message omitted.

   * CVE-2014-8275 (bsc#912018): Fixed various certificate fingerprint issues.

   * CVE-2015-0204 (bsc#912014): Only allow ephemeral RSA keys in export
     ciphersuites

   * CVE-2015-0205 (bsc#912293): A fixwas added to prevent use of DH client
     certificates without sending certificate verify message.

   * CVE-2015-0206 (bsc#912292): A memory leak was fixed in
     dtls1_buffer_record.

References:

   http://support.novell.com/security/cve/CVE-2014-3569.html
   http://support.novell.com/security/cve/CVE-2014-3570.html
   http://support.novell.com/security/cve/CVE-2014-3571.html
   http://support.novell.com/security/cve/CVE-2014-3572.html
   http://support.novell.com/security/cve/CVE-2014-8275.html
   http://support.novell.com/security/cve/CVE-2015-0204.html
   http://support.novell.com/security/cve/CVE-2015-0205.html
   http://support.novell.com/security/cve/CVE-2015-0206.html
   https://bugzilla.suse.com/show_bug.cgi?id=911399
   https://bugzilla.suse.com/show_bug.cgi?id=912014
   https://bugzilla.suse.com/show_bug.cgi?id=912015
   https://bugzilla.suse.com/show_bug.cgi?id=912018
   https://bugzilla.suse.com/show_bug.cgi?id=912292
   https://bugzilla.suse.com/show_bug.cgi?id=912293
   https://bugzilla.suse.com/show_bug.cgi?id=912294
   https://bugzilla.suse.com/show_bug.cgi?id=912296
2015-01-24 01:01:54 +00:00
archivers simplify MASTER_SITES subdirectory. 2015-01-23 06:22:20 +00:00
audio Update to 0.8.0 2015-01-23 00:16:03 +00:00
benchmarks Update HOMEPAGE, was 404. 2015-01-20 06:43:09 +00:00
biology Update HOMEPAGE, was Host Unknown. But the link to download still gets 404. 2014-12-20 12:02:28 +00:00
bootstrap remove obsolated information for bootstrap kit and binary packages. 2015-01-19 00:12:43 +00:00
cad Update tkgate to 1.8.7. Patch provided by Edgar Fuss in PR pkg/49482, 2015-01-17 14:48:56 +00:00
chat add patch to help configure find openssl 2015-01-19 12:22:51 +00:00
comms Switch license to modified-bsd. Move socks4 option over to use dante. 2015-01-17 15:30:03 +00:00
converters Revbump associated with update of lang/ocaml. 2015-01-20 14:24:34 +00:00
cross PKGREVISION++, by converting (duplicated) libconfuse to confuse. Thanks gdt@. 2015-01-18 06:18:58 +00:00
databases Apply strtoi fix for NetBSD/current to all PostgreSQL versions. 2015-01-23 15:06:00 +00:00
devel Patches to build on SunOS (OI here) 2015-01-23 14:31:38 +00:00
distfiles
doc Updated print/abcm2ps to 7.8.12 2015-01-24 00:58:45 +00:00
editors editors/lyx: update to 2.1.2.2 2015-01-10 18:13:22 +00:00
emulators Apply following update to suse131_openssl, bump PKGREVISION. 2015-01-24 01:01:54 +00:00
filesystems recuesive bump from libarchive major update. 2015-01-21 09:12:41 +00:00
finance Update to 2.6.5, switch to yelp3 since it has a higher chance of 2015-01-06 15:03:01 +00:00
fonts Update to 1.1.2: 2015-01-17 09:12:53 +00:00
games + ioquake3-raspberrypi 2015-01-22 12:51:27 +00:00
geography Update opencpn to 4.0.0. Changes since 3.2.2: 2015-01-22 12:34:15 +00:00
graphics Check for aligned memory functions with cmake 2015-01-23 17:15:09 +00:00
ham Update gnuradio-core (and others) from 3.7.5 to 3.7.5.1 2015-01-16 12:56:40 +00:00
inputmethod Update ibus-array to 0.1.0. 2015-01-20 11:24:33 +00:00
lang Update php56 to 5.6.5. 2015-01-23 16:11:38 +00:00
licenses skype21-license: Arise from your grave! and be used by wip/skype4. 2014-12-04 19:59:58 +00:00
mail Update rspamd to 0.8.1 2015-01-23 21:47:44 +00:00
math Rename private strtoi function. Bump revision. 2015-01-23 15:07:53 +00:00
mbone Re-do the get_timestamp() patch to instead of calling times() use 2015-01-13 20:25:13 +00:00
meta-pkgs Don't use plain "throw;", it breaks clang -fno-exceptions build. Bump 2015-01-15 13:01:44 +00:00
misc Revbump associated with update of lang/ocaml. 2015-01-20 14:24:34 +00:00
mk Added ocaml-tyxml option (for devel/js_of_ocaml) 2015-01-20 15:55:19 +00:00
multimedia Fix build on NetBSD-current with strtoi. 2015-01-23 16:15:42 +00:00
net tell pidfile name 2015-01-23 08:09:37 +00:00
news Use BROKEN_EXCEPT_ON_PLATFORM for where configs have to be created manually. 2015-01-01 11:19:28 +00:00
packages
parallel Fold PLIST.Linux into PLIST using more plist vars, and add more files 2015-01-15 20:51:11 +00:00
pkgtools Add AC_SYS_LARGEFILE to files/configure.ac 2015-01-22 18:15:39 +00:00
print Update 6.6.6 to 7.8.12 2015-01-24 00:58:36 +00:00
regress Do not use a naked "make", instead use TEST_MAKE. Now it fails differently. 2014-06-21 16:34:13 +00:00
security Not MAKE_JOBS_SAFE. 2015-01-23 15:09:26 +00:00
shells Install complete.tcsh and csh-mode.el files as example files. 2015-01-20 11:00:32 +00:00
sysutils Add some bug report URLs. 2015-01-23 10:11:47 +00:00
templates
textproc Fix build with cmake-3.1. 2015-01-23 14:09:36 +00:00
time Revbump associated with update of lang/ocaml. 2015-01-20 14:24:34 +00:00
wm Tell configure explicitly where to look for X11 headers and libs. 2015-01-21 15:22:14 +00:00
www Remove contao33 (Contao Open Source CMS 3.3.x) package since it was 2015-01-23 16:19:14 +00:00
x11 Don't depend on the optimizer inlining a function to get immediates in 2015-01-23 15:10:51 +00:00
Makefile
pkglocate
README

$NetBSD: README,v 1.18 2005/05/07 22:18:28 wiz Exp $

Please see doc/pkgsrc.txt for information.