Thanks for taking on this update; I have a few questions: The changelog references a patch that isn't included:
+ - debian/patches/fix_renegotiation.patch: add upstream commit to fix + renegotiation in ssl/s3_clnt.c, ssl/t1_lib.c. Why was this patch dropped? It feels accidental, since it's still in the changelog. The modifications to the file crypto/cms/cms_smime.c appear to have been dropped from debian/patches/CVE-2012-0884.patch. Was this intentional? Thanks ** Changed in: openssl (Ubuntu Precise) Status: Confirmed => Incomplete ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-0884 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1331452 Title: Please backport current CVEs for Precise LTS openssl098 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1331452/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs