[LFS Trac] #5644: openssl-3.4.1

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5644: openssl-3.4.1
-------------------------+----------------------
 Reporter:  Bruce Dubbs  |      Owner:  lfs-book
     Type:  enhancement  |     Status:  new
 Priority:  normal       |  Milestone:  12.3
Component:  Book         |    Version:  git
 Severity:  normal       |   Keywords:
-------------------------+----------------------
 New point version with security updates.

 Changes between 3.4.0 and 3.4.1 [11 Feb 2025]

 * Fixed RFC7250 handshakes with unauthenticated servers don't abort as
 expected.
   ([CVE-2024-12797])

 * Fixed timing side-channel in ECDSA signature computation.
   ([CVE-2024-13176])

  * Reverted the behavior change of CMS_get1_certs() and CMS_get1_crls()
    that happened in the 3.4.0 release. These functions now return NULL
    again if there are no certs or crls in the CMS object.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5644>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.