Hello community, here is the log from the commit of package openssl-1_0_0 for openSUSE:Leap:15.2 checked in at 2020-01-19 15:47:00 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Leap:15.2/openssl-1_0_0 (Old) and /work/SRC/openSUSE:Leap:15.2/.openssl-1_0_0.new.26092 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openssl-1_0_0" Sun Jan 19 15:47:00 2020 rev:27 rq:762876 version:1.0.2p Changes: -------- --- /work/SRC/openSUSE:Leap:15.2/openssl-1_0_0/openssl-1_0_0.changes 2020-01-15 15:37:17.311021910 +0100 +++ /work/SRC/openSUSE:Leap:15.2/.openssl-1_0_0.new.26092/openssl-1_0_0.changes 2020-01-19 15:47:10.741691693 +0100 @@ -1,0 +2,8 @@ +Tue Dec 10 16:04:06 UTC 2019 - Pedro Monreal Gonzalez <[email protected]> + +- Security fix: [bsc#1158809, CVE-2019-1551] + * Overflow bug in the x64_64 Montgomery squaring procedure used + in exponentiation with 512-bit moduli +- Add openssl-1_1-CVE-2019-1551.patch + +------------------------------------------------------------------- New: ---- openssl-1_1-CVE-2019-1551.patch ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openssl-1_0_0.spec ++++++ --- /var/tmp/diff_new_pack.oTNoqb/_old 2020-01-19 15:47:12.053692470 +0100 +++ /var/tmp/diff_new_pack.oTNoqb/_new 2020-01-19 15:47:12.057692473 +0100 @@ -115,9 +115,11 @@ Patch110: openssl-CVE-2019-1547.patch Patch111: openssl-CVE-2019-1563.patch Patch113: 0001-RT-4242-reject-invalid-EC-point-coordinates.patch +# OpenSSL Security Advisory [6 December 2019] bsc#1158809 CVE-2019-1551 +# PATCH-FIX-UPSTREAM Integer overflow in RSAZ modular exponentiation on x86_64 +Patch114: openssl-1_1-CVE-2019-1551.patch # steam patches Patch999: openssl-fix-cpuid_setup.patch - BuildRequires: bc BuildRequires: ed BuildRequires: pkgconfig @@ -275,6 +277,7 @@ %patch110 -p1 %patch111 -p1 %patch113 -p1 +%patch114 -p1 # clean up patching leftovers find . -name '*.orig' -delete ++++++ openssl-1_1-CVE-2019-1551.patch ++++++ ++++ 765 lines (skipped)
