[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-09 Thread Jamie Strandboge
** Changed in: openslp-dfsg (Ubuntu) Importance: High = Medium -- OpenSSL signature verification API misuses https://bugs.launchpad.net/bugs/314776 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to bind9 in ubuntu. --

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-09 Thread Jamie Strandboge
openslp as of 1.2.1-5 (the one shipped in Dapper), doesn't build with --enable-security and in fact Build-Conflicts against libssl-dev (see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=337606), so the package would need significant changes to be affected by this bug. ** Changed in:

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-08 Thread Jamie Strandboge
ntp (1:4.2.4p4+dfsg-7ubuntu3) jaunty; urgency=low * SECURITY UPDATE: clients treat malformed signatures as good when verifying server DSA and ECDSA certificates. - debian/patches/CVE-2009-0021.patch: update ntpd/ntp_crypto.c to properly check the return code of EVP_VerifyFinal()

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-08 Thread Jamie Strandboge
NTP issue is fixed in http://www.ubuntu.com/usn/usn-705-1. -- OpenSSL signature verification API misuses https://bugs.launchpad.net/bugs/314776 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to bind9 in ubuntu. -- Ubuntu-server-bugs

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-08 Thread Jamie Strandboge
** Changed in: ntp (Ubuntu) Importance: High = Medium ** Changed in: bind9 (Ubuntu) Importance: High = Medium -- OpenSSL signature verification API misuses https://bugs.launchpad.net/bugs/314776 You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-08 Thread Jamie Strandboge
Bind9 is fixed in http://www.ubuntu.com/usn/usn-706-1. -- OpenSSL signature verification API misuses https://bugs.launchpad.net/bugs/314776 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to bind9 in ubuntu. -- Ubuntu-server-bugs mailing

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-07 Thread Jamie Strandboge
Thank you for using Ubuntu and taking the time to report a bug. ** Changed in: openssl (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) Status: New = Fix Committed ** Changed in: ntp (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) Status: New =

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-07 Thread Jamie Strandboge
OpenSSL issue is fixed in http://www.ubuntu.com/usn/usn-704-1. ** Changed in: openssl (Ubuntu) Status: Fix Committed = Fix Released -- OpenSSL signature verification API misuses https://bugs.launchpad.net/bugs/314776 You received this bug notification because you are a member of Ubuntu

[Bug 314776] Re: OpenSSL signature verification API misuses

2009-01-07 Thread Jamie Strandboge
openssl (0.9.8g-14ubuntu2) jaunty; urgency=low * SECURITY UPDATE: clients treat malformed signatures as good when verifying server DSA and ECDSA certificates - update apps/speed.c, apps/spkac.c, apps/verify.c, apps/x509.c, ssl/s2_clnt.c, ssl/s2_srvr.c, ssl/s3_clnt.c, s3_srvr.c,