Bug#444435: [Pkg-openssl-devel] Bug#444435: openssl: [CVE-2007-5135] Off-by-one error in the SSL_get_shared_ciphers()

2007-09-28 Thread Kurt Roeckx
On Fri, Sep 28, 2007 at 07:16:15PM +0200, Kurt Roeckx wrote: > > Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL > > 0.9.7l and 0.9.8d might allow remote attackers to execute arbitrary > > code via a crafted packet that triggers a one-byte buffer underflow. So, it seems to be th

Bug#444435: [Pkg-openssl-devel] Bug#444435: openssl: [CVE-2007-5135] Off-by-one error in the SSL_get_shared_ciphers()

2007-09-28 Thread Kurt Roeckx
tags 35 - sarge etch clone 35 -1 reassign -1 openssl097 0.9.7k-3.1 thanks On Fri, Sep 28, 2007 at 04:16:02PM +0200, Axel Beckert wrote: > Package: openssl > Version: 0.9.8c-4, 0.9.7e-3sarge4 > Severity: critical > Tags: sarge, etch, security Since this applies to sid (and oldstable) too,