Re: [OE-core] [rocko][PATCH v3 1/4] openssl10: Upgrade 1.0.2l -> 1.0.2m

2017-12-21 Thread Koen Kooi
> Op 19 dec. 2017, om 22:26 heeft Stefan Agner het volgende > geschreven: > > From: Stefan Agner > > Deals with two CVEs: > * bn_sqrx8x_internal carry bug on x86_64 (CVE-2017-3736) > * Malformed X.509 IPAddressFamily could cause OOB read (CVE-2017-3735) > > Signed-off-by: Stefan Agner > Ac

[OE-core] [rocko][PATCH v3 1/4] openssl10: Upgrade 1.0.2l -> 1.0.2m

2017-12-19 Thread Stefan Agner
From: Stefan Agner Deals with two CVEs: * bn_sqrx8x_internal carry bug on x86_64 (CVE-2017-3736) * Malformed X.509 IPAddressFamily could cause OOB read (CVE-2017-3735) Signed-off-by: Stefan Agner Acked-by: Otavio Salvador --- Changes since v2: - Rebased to rocko-next .../0001-Fix-build-with-