More OpenSSL security fixes

Discussion in 'privacy technology' started by BoerenkoolMetWorst, Aug 7, 2014.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    Forthcoming OpenSSL Release
    https://mta.openssl.org/pipermail/openssl-announce/2020-April/000170.html

    Note in particular these words:
    The highest severity issue fixed in this release is HIGH
     
  2. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    OpenSSL version 1.1.1g published - 21 April 2020
    https://mta.openssl.org/pipermail/openssl-announce/2020-April/000171.html

    https://www.openssl.org/news/secadv/20200421.txt
    (emphasis by me)
     
  3. guest

    guest Guest

    Expert released PoC exploit for CVE-2020-1967 DoS flaw in OpenSSL
    May 5, 2020
    https://securityaffairs.co/wordpress/102763/hacking/cve-2020-1967-dos-openssl-exploit.html
     
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    Security Policy Update on Prenotifications
    Posted by Mark J Cox , May 12th, 2020
    https://www.openssl.org/blog/blog/2020/05/12/security-prenotifications/

    Read more there
     
  5. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    OpenSSL 3.0 Alpha2 Release
    Posted by Nicola Tuveri , May 16th, 2020
    https://www.openssl.org/blog/blog/2020/05/16/OpenSSL3.0Alpha2/

    Read more there
     
  6. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    OpenSSL 3.0 Alpha4 Release
    Posted by Nicola Tuveri , Jun 25th, 2020 7:00 pm
    https://www.openssl.org/blog/blog/2020/06/25/OpenSSL3.0Alpha4/
    Read more there for all the details.
     
  7. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  8. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  9. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  10. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  11. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  12. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    Forthcoming OpenSSL Release

    01 Dec 2020

    https://mta.openssl.org/pipermail/openssl-announce/2020-December/000186.html

    PS: Note by me:
    I think that there is a little typo there.
    The message mentions both 1.1.1i and 1.1.i
    Shouldn't that 1.1.1i be the right one?
     
    Last edited: Dec 1, 2020
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,867
    Location:
    Outer space
    Yes, I think so, as 1.1.i would be 1.1.0i and that release is already from August 2018.
    In addition, it also looks like the 1.1.0 branch is EOL, as the last version is 1.1.0l, released September 2019.
     
  14. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,052
    Location:
    Texas
    OpenSSL Releases Security Update
     
  15. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    Thanks Ron!

    The OpenSSL Security Advisory :
    https://www.openssl.org/news/secadv/20201208.txt

    (emphasis by me)
     
  16. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  17. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  18. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,402
    Yep, Debian updated SSL stuff a few days ago.
     
  19. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  20. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    Forthcoming OpenSSL release -> 25 Mar 2021

    https://mta.openssl.org/pipermail/openssl-announce/2021-March/000196.html

    PS: emphasis by me.
     
    Last edited: Mar 25, 2021
  21. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    OpenSSL 1.1.1k is now available, including bug and security fixes - 25-Mar-2021
    https://www.openssl.org/news/newslog.html

    For details see:
    https://www.openssl.org/news/secadv/20210325.txt

     
  22. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,402
    Debian has already added them to apt-get. Running slick!
     
  23. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
    OpenSSL 3.0 Release Candidate - 17 June 2021
    https://www.openssl.org/blog/blog/2021/06/17/OpenSSL3.0ReleaseCandidate/

    Read more there for some of the highlights!
     
  24. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,638
  25. guest

    guest Guest

    OpenSSL Vulnerability Can Be Exploited to Change Application Data
    August 24, 2021
    https://www.securityweek.com/openssl-vulnerability-can-be-exploited-change-application-data
    OpenSSL Announcements
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.