Thanks for taking on this update; I have a few questions:
The changelog references a patch that isn't included:
+ - debian/patches/fix_renegotiation.patch: add upstream commit to fix
+ renegotiation in ssl/s3_clnt.c, ssl/t1_lib.c.
Why was this patch dropped? It feels accidental, since it's still in the
changelog.
The modifications to the file crypto/cms/cms_smime.c appear to have been
dropped from debian/patches/CVE-2012-0884.patch. Was this intentional?
Thanks
** Changed in: openssl (Ubuntu Precise)
Status: Confirmed => Incomplete
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2012-0884
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1331452
Title:
Please backport current CVEs for Precise LTS openssl098
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1331452/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs