Bug 8452

Summary: [UPDATE REQUEST 2014.1] openssl 1.0.2m
Product: [ROSA-based products] ROSA Fresh Reporter: Алзим <alzim>
Component: Packages from MainAssignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: andrey.bondrov, v.potapov
Version: FreshFlags: v.potapov: qa_verified+
andrey.bondrov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Platform: --- ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Алзим 2017-11-03 01:12:48 MSK
Доступны корректирующие выпуски криптографической библиотеки OpenSSL 1.0.2m и 1.1.0g , в которых устранены две уязвимости, из которых одна отмечена как неопасная (CVE-2017-3735), а вторая (CVE-2017-3736) отнесена к категории проблем среднего уровня опасности.
Comment 1 Алзим 2017-11-03 01:18:57 MSK
Updated to 1.0.2m 
https://abf.io/build_lists/2907786
https://abf.io/build_lists/2907787
Comment 2 Vladimir Potapov 2017-11-08 19:52:43 MSK
The update is sent to expanded testing
*****************************************
Comment 3 Andrey Bondrov 2017-11-09 11:15:49 MSK
Advisory: "Update OpenSSL to new version 1.0.2m. Build additional libcrypto.so.10 and libssl.so.10 library packages for compatibility with RHEL/Fedora (needed for some non-free software)"

https://abf.rosalinux.ru/build_lists/2909200
https://abf.rosalinux.ru/build_lists/2909201
Comment 4 Vladimir Potapov 2017-11-09 15:39:50 MSK
The update is sent to expanded testing
************************************
Comment 5 Vladimir Potapov 2017-11-13 18:12:53 MSK
openssl-1.0.2m-2
https://abf.rosalinux.ru/build_lists/2909200
https://abf.rosalinux.ru/build_lists/2909201
*************************** Advisory ******************************
Fix (CVE-2017-3735) and  (CVE-2017-3736). Update OpenSSL to new version 1.0.2m. Build additional libcrypto.so.10 and libssl.so.10 library packages for compatibility with RHEL/Fedora (needed for some non-free software)
********************************************************************
QA Verified