-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 15 Jun 2014 12:31:21 +0200 Source: openssl Binary: openssl libssl1.0.0 libcrypto1.0.0-udeb libssl-dev libssl-doc libssl1.0.0-dbg Architecture: source all amd64 Version: 1.0.1e-2+deb7u11 Distribution: wheezy-security Urgency: medium Maintainer: Debian OpenSSL Team <pkg-openssl-devel@lists.alioth.debian.org> Changed-By: Kurt Roeckx <kurt@roeckx.be> Description: libcrypto1.0.0-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl-doc - SSL development documentation documentation libssl1.0.0 - SSL shared libraries libssl1.0.0-dbg - Symbol tables for libssl and libcrypto openssl - Secure Socket Layer (SSL) binary and related cryptographic tools Closes: 728055 751093 751457 Changes: openssl (1.0.1e-2+deb7u11) wheezy-security; urgency=medium . * Update fix for CVE-2014-0224 to work with more renegiotation and resumption cases. (Closes: #751093) * Fix CVE-2012-4929 (CRiME) by disabling zlib compression by default. It can be enabled again by setting the environment variable OPENSSL_NO_DEFAULT_ZLIB. (Closes: #728055) * Update ECDHE-ECDSA_Safari.patch to define SSL_OP_MSIE_SSLV2_RSA_PADDING again but to 0 so things keep building. (Closes: #751457) Checksums-Sha1: 5fd0a0d155aa9a8e66860bc3cd3fe4cc702b550d 2218 openssl_1.0.1e-2+deb7u11.dsc 696c96ec8dbebddaa91ef19482f831d3b08d2a26 107031 openssl_1.0.1e-2+deb7u11.debian.tar.gz ae0071cc8bc3bd8e9ae20494b388a3011760bddc 1198118 libssl-doc_1.0.1e-2+deb7u11_all.deb 13ff5b9292976061041307d4c991507fb40d2b6f 700568 openssl_1.0.1e-2+deb7u11_amd64.deb 4c1e126254ef9e96528662115a89f80bf3bfc347 1258274 libssl1.0.0_1.0.1e-2+deb7u11_amd64.deb 01348e48de3a4a8a104a6fb73dbde82ae3edf0df 635590 libcrypto1.0.0-udeb_1.0.1e-2+deb7u11_amd64.udeb 822bcf5e7ac1bba83a1f2a4d690ad381a3c2ee7b 1752950 libssl-dev_1.0.1e-2+deb7u11_amd64.deb 06ab15accd32b555c6594e85908f4c4b2afc55aa 3079246 libssl1.0.0-dbg_1.0.1e-2+deb7u11_amd64.deb Checksums-Sha256: 9629ccae5a85fa16134fdde8fb35f75ea619f1c3ea34196b64fd9aa1233d876c 2218 openssl_1.0.1e-2+deb7u11.dsc 195640b6461ea75041e370511048c60850018fb0475434b411a0b9c6a4e6d8fc 107031 openssl_1.0.1e-2+deb7u11.debian.tar.gz 5ac00f989b9541d5cb9fc973f5e75f2a93c94f3c309a1fc10db5081288fedaca 1198118 libssl-doc_1.0.1e-2+deb7u11_all.deb dd17977ac71c4f5649e3458e8617e6d29432a0e2643ec6365dc41fad0e210b53 700568 openssl_1.0.1e-2+deb7u11_amd64.deb 9c3192a41bb485b2d195379ce665a903673b923c422a0b3624a608d03e98c22a 1258274 libssl1.0.0_1.0.1e-2+deb7u11_amd64.deb 5382fbf0360dcccf93caf83726e493cc83872549ce0c148c08485f45bb7eeedf 635590 libcrypto1.0.0-udeb_1.0.1e-2+deb7u11_amd64.udeb 043d5ff3e795177d3bdb75de544287d8a398789f7be26b6e934d186d5c6dcf90 1752950 libssl-dev_1.0.1e-2+deb7u11_amd64.deb 72e9885b7adf1dc37d457978428a900f27f3174722c2651955cbdff4f165e85b 3079246 libssl1.0.0-dbg_1.0.1e-2+deb7u11_amd64.deb Files: 2bd140fe21d5b0a7f3c0073545bed220 2218 utils optional openssl_1.0.1e-2+deb7u11.dsc 33fc2c3e043c29babfcbf069127e0f2c 107031 utils optional openssl_1.0.1e-2+deb7u11.debian.tar.gz e616cdc012f0f2dba5443823076b4d4f 1198118 doc optional libssl-doc_1.0.1e-2+deb7u11_all.deb b0580165afaa58eac495f03c2866d50c 700568 utils optional openssl_1.0.1e-2+deb7u11_amd64.deb d2f8ef40b6f6a293b3564ea53aa34bf8 1258274 libs important libssl1.0.0_1.0.1e-2+deb7u11_amd64.deb 03a0910d215131ea009388e1e243956d 635590 debian-installer optional libcrypto1.0.0-udeb_1.0.1e-2+deb7u11_amd64.udeb be44c729349da5aff10eafee607c4d78 1752950 libdevel optional libssl-dev_1.0.1e-2+deb7u11_amd64.deb fc6d50c06db6df8f72cbc37e7703f1d0 3079246 debug extra libssl1.0.0-dbg_1.0.1e-2+deb7u11_amd64.deb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJTnYWgAAoJEKGfLDAaVSLdKxEQAK0sXG4HRTxQ/0ViFEsmUQ+x CneYr0ETx4nkFnGIJFvG8A/Y5huljky/Ar8mnz1ONK7f+faJy9yzKsNLNYLBDpmy fS+v0jFAW+9LeoIQ4pfR2ludYDwMpGsYiKbcHszGk+kh6RKlpsZ+igZGSnlvyfJN Va3VO3X08z0ZBs+oTvsNED0RmXuomd+NYcv83Z+uO0qQJrPZIJD+nZE7waoLMrH8 DlBHbCKNLKSV2zQHU0IYTRfOKScwEz0GQMkjU7QbblaKGLRBASkD7acLUfWQhVOo KCWpQ86YPr05VmcukjJrX9+SHmWWEnP6O9SwGI7FOps9voR5vKKSF65A1tHy6GSC hDF8WImMz3Xe+d2g3E6G0bYKgEFyxgrsoZHeNo1X78o0lV/dr3wasgQuR1ZuDd0L /zl7u4os4uZ05RjBq7SQkBkduQydlhsUS3KOPO10YBdW+d2px2OG/RYTsoJscWYb TC6d7k1ic1CtM9y11dlLdw6fQiaZRzVVvtKTN2QVv5hmAiKMkXJdJze+qLGwcsHF pfR2ZI+42TzTiPVPAJaBwCenmLJYjcf51JvEHum2AdOA1eG0wuE8Y0kJdHy+8wu3 LI97X7h4IkaQ7NmCuws1ns2cad7DTpUSbW4+nlxk3mADgNw7hs5zenMTURH/UhUj V2lnvQA3hA9v8HJea+f7 =2qd/ -----END PGP SIGNATURE-----