From owner-freebsd-security@FreeBSD.ORG Sat Jun 13 09:09:29 2015 Return-Path: Delivered-To: freebsd-security@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id DBF38908 for ; Sat, 13 Jun 2015 09:09:29 +0000 (UTC) (envelope-from dim@FreeBSD.org) Received: from tensor.andric.com (unknown [IPv6:2001:7b8:3a7:0:20e:cff:fea0:e4a2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "tensor.andric.com", Issuer "COMODO RSA Domain Validation Secure Server CA" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 9B47CE91 for ; Sat, 13 Jun 2015 09:09:29 +0000 (UTC) (envelope-from dim@FreeBSD.org) Received: from [IPv6:2001:7b8:3a7::ad7a:6fe0:9873:3fb4] (unknown [IPv6:2001:7b8:3a7:0:ad7a:6fe0:9873:3fb4]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by tensor.andric.com (Postfix) with ESMTPSA id BF1CC21955; Sat, 13 Jun 2015 11:09:23 +0200 (CEST) Subject: Re: FreeBSD Security Advisory FreeBSD-SA-15:10.openssl Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2098\)) Content-Type: multipart/signed; boundary="Apple-Mail=_E808DF3C-30FE-4F69-A6FD-F43EB02E753D"; protocol="application/pgp-signature"; micalg=pgp-sha1 X-Pgp-Agent: GPGMail 2.5 From: Dimitry Andric In-Reply-To: <20150613031307.GA30499@knossos> Date: Sat, 13 Jun 2015 11:09:15 +0200 Cc: freebsd-security@freebsd.org Message-Id: <44F32106-F54A-40F6-9360-5F0904EF6C8B@FreeBSD.org> References: <20150613031307.GA30499@knossos> To: Zoran Kolic X-Mailer: Apple Mail (2.2098) X-Mailman-Approved-At: Sat, 13 Jun 2015 11:25:23 +0000 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 13 Jun 2015 09:09:29 -0000 --Apple-Mail=_E808DF3C-30FE-4F69-A6FD-F43EB02E753D Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=us-ascii On 13 Jun 2015, at 05:13, Zoran Kolic wrote: > > Do I read this advisory correctly: it does not affect 9.3? It *does* affect 9.3: > Category: contrib > Module: openssl > Announced: 2015-06-12 > Affects: All supported versions of FreeBSD. > Corrected: 2015-06-11 19:07:45 UTC (stable/10, 10.1-STABLE) > 2015-06-12 07:23:55 UTC (releng/10.1, 10.1-RELEASE-p12) > 2015-06-11 19:39:27 UTC (stable/9, 9.3-STABLE) > 2015-06-12 07:23:55 UTC (releng/9.3, 9.3-RELEASE-p16) > 2015-06-11 19:39:27 UTC (stable/8, 8.4-STABLE) > 2015-06-12 07:23:55 UTC (releng/8.4, 8.4-RELEASE-p30) > CVE Name: CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791 > CVE-2015-1792, CVE-2015-4000 You need 9.3-RELEASE-p16 to fix it. -Dimitry --Apple-Mail=_E808DF3C-30FE-4F69-A6FD-F43EB02E753D Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.27 iEYEARECAAYFAlV780YACgkQsF6jCi4glqMJwwCeOr7ZPxg2E6wkc+Cl3vtd/oAn wOoAoMFLuiAY2/KlZI26V784PKpJNQXc =2NKR -----END PGP SIGNATURE----- --Apple-Mail=_E808DF3C-30FE-4F69-A6FD-F43EB02E753D--