Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-10 Thread Moritz Muehlenhoff
On Fri, Jan 09, 2009 at 12:53:42PM +0100, Thijs Kinkhorst wrote: > Hi Fredric, > > On Fri, January 9, 2009 12:00, Frederic Peters wrote: > > I uploaded 2.2.1-2 to unstable; I also applied the fix to 0.6.5 > > (etch), but I don't have ressources to build it, it is available here: > > http://people.

Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-09 Thread Thijs Kinkhorst
Hi Fredric, On Fri, January 9, 2009 12:00, Frederic Peters wrote: > I uploaded 2.2.1-2 to unstable; I also applied the fix to 0.6.5 > (etch), but I don't have ressources to build it, it is available here: > http://people.debian.org/~fpeters/lasso_0.6.5-3.etch.1.diff.gz Many thanks for your work!

Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-09 Thread Frederic Peters
Hello, Moritz Muehlenhoff wrote: > Package: lasso > Severity: grave > Tags: security > Justification: user security hole > > Please see the following references for lasso and the recent > OpenSSL issue: > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0050 > http://www.ocert.org/advisor

Bug#511262: CVE-2009-0050: Insufficient certificate validation

2009-01-08 Thread Moritz Muehlenhoff
Package: lasso Severity: grave Tags: security Justification: user security hole Please see the following references for lasso and the recent OpenSSL issue: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0050 http://www.ocert.org/advisories/ocert-2008-016.html Cheers, Moritz -- S