Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

openssl: CVE-2016-0701, CVE-2015-3197 #1389

Closed
3 of 11 tasks
tianon opened this issue Jan 28, 2016 · 3 comments
Closed
3 of 11 tasks

openssl: CVE-2016-0701, CVE-2015-3197 #1389

tianon opened this issue Jan 28, 2016 · 3 comments

Comments

@tianon
Copy link
Member

tianon commented Jan 28, 2016

CVE-2016-0701, CVE-2015-3197

https://www.openssl.org/news/secadv/20160128.txt

CVE-2016-0701: https://www.openssl.org/news/vulnerabilities.html#2016-0701

  • Fixed in OpenSSL 1.0.2f (Affected 1.0.2e, 1.0.2d, 1.0.2c, 1.0.2b, 1.0.2a, 1.0.2)

CVE-2015-3197: https://www.openssl.org/news/vulnerabilities.html#2015-3197

  • Fixed in OpenSSL 1.0.1r (Affected 1.0.1q, 1.0.1p, 1.0.1o, 1.0.1n, 1.0.1m, 1.0.1l, 1.0.1k, 1.0.1j, 1.0.1i, 1.0.1h, 1.0.1g, 1.0.1f, 1.0.1e, 1.0.1d, 1.0.1c, 1.0.1b, 1.0.1a, 1.0.1)
  • Fixed in OpenSSL 1.0.2f (Affected 1.0.2e, 1.0.2d, 1.0.2c, 1.0.2b, 1.0.2a, 1.0.2)

@Djelibeybi
Copy link
Contributor

Oracle Linux is not affected by CVE-2016-0701 but is affected by CVE-2015-3197. Our security team is currently evaluating whether to release an update for this CVE given the low impact.

@tianon
Copy link
Member Author

tianon commented Jan 28, 2016

GitHub's email gateway appears to be struggling today: Cool, thanks for the update! It's looking like that's a pretty common result of this so far. 👍

@tianon
Copy link
Member Author

tianon commented Feb 17, 2016

Given the age and relative severity of this vulnerability and in light of #1448 getting a rebuild for most major bits anyhow, I'm going to close this and declare it generally either FIXED, PENDING, or WONTFIX (and thus really nothing more we can do here).

@tianon tianon closed this as completed Feb 17, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants