From ce063e4989a7f9b895e663e649df14b1d8433121 Mon Sep 17 00:00:00 2001 From: Brent Cook Date: Thu, 11 Jun 2015 09:00:29 -0500 Subject: 2.1.7 security update --- ChangeLog | 16 ++++++++++++++++ VERSION | 2 +- 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 7c1bb29..d5c23fc 100644 --- a/ChangeLog +++ b/ChangeLog @@ -31,6 +31,22 @@ LibreSSL Portable Release Notes: This release primarily addresses a number of security issues in coordination with the OpenSSL project. +2.1.7 - Security Update + + * Fixes for the following issues are integrated into LibreSSL 2.1.7: + - CVE-2015-1788 - Malformed ECParameters causes infinite loop + - CVE-2015-1789 - Exploitable out-of-bounds read in X509_cmp_time + - CVE-2015-1792 - CMS verify infinite loop with unknown hash function + + * The following CVEs did not apply to LibreSSL or were fixed in + earlier releases: + - CVE-2015-4000 - DHE man-in-the-middle protection (Logjam) + - CVE-2015-1790 - PKCS7 crash with missing EnvelopedContent + - CVE-2014-8176 - Invalid free in DTLS + + * Fixes for the following CVEs are still in review for LibreSSL + - CVE-2015-1791 - Race condition handling NewSessionTicket + 2.1.6 - Security update * Fixes for the following issues are integrated into LibreSSL 2.1.6: diff --git a/VERSION b/VERSION index 399088b..04b10b4 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -2.1.6 +2.1.7 -- cgit v1.2.3-55-g6feb