Skip to content
This repository was archived by the owner on Nov 9, 2017. It is now read-only.

Conversation

@kusma
Copy link
Member

@kusma kusma commented Jun 5, 2014

The OpenSSL developers released a new security advisory today:
http://www.openssl.org/news/secadv_20140605.txt

Unlike with Heartbleed, this advisory discloses vulnerabilities that affects our version. So let's upgrade.

kusma added 4 commits June 5, 2014 17:33
On advice from OpenSSL Security Advisory [05 Jun 2014], we should
upgrade OpenSSL to version 0.9.8za ASAP. CVE-2014-0195 is
especially nasty, as it allows arbitrary code execution.

http://www.openssl.org/news/secadv_20140605.txt

Include a patch to make sure this compiles.

Signed-off-by: Erik Faye-Lund <[email protected]>
Signed-off-by: Erik Faye-Lund <[email protected]>
dscho added a commit that referenced this pull request Jun 5, 2014
@dscho dscho merged commit d616606 into msysgit:master Jun 5, 2014
@dscho
Copy link
Member

dscho commented Jun 5, 2014

Thanks!

@kusma kusma deleted the upgrade-openssl branch July 29, 2016 13:10
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants