Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-10 Thread Moritz Muehlenhoff
On Fri, Jan 09, 2009 at 12:53:42PM +0100, Thijs Kinkhorst wrote: Hi Fredric, On Fri, January 9, 2009 12:00, Frederic Peters wrote: I uploaded 2.2.1-2 to unstable; I also applied the fix to 0.6.5 (etch), but I don't have ressources to build it, it is available here:

Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-09 Thread Frederic Peters
Hello, Moritz Muehlenhoff wrote: Package: lasso Severity: grave Tags: security Justification: user security hole Please see the following references for lasso and the recent OpenSSL issue: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0050

Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-09 Thread Thijs Kinkhorst
Hi Fredric, On Fri, January 9, 2009 12:00, Frederic Peters wrote: I uploaded 2.2.1-2 to unstable; I also applied the fix to 0.6.5 (etch), but I don't have ressources to build it, it is available here: http://people.debian.org/~fpeters/lasso_0.6.5-3.etch.1.diff.gz Many thanks for your work!

Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-08 Thread Moritz Muehlenhoff
Package: lasso Severity: grave Tags: security Justification: user security hole Please see the following references for lasso and the recent OpenSSL issue: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0050 http://www.ocert.org/advisories/ocert-2008-016.html Cheers, Moritz --