OpenSSL version 1.0.0l released
Openssl project has announced a new realse of openssl 1.0.01 open source toolkit for SSl/TLS.The new release has fixed several bugs as the following :
Major changes between OpenSSL 1.0.0k and OpenSSL 1.0.0l [6 Jan 2014]
- Fix for DTLS retransmission bug CVE-2013-6450
Major changes between OpenSSL 1.0.0j and OpenSSL 1.0.0k [5 Feb 2013]:
- Fix for SSL/TLS/DTLS CBC plaintext recovery attack CVE-2013-0169
- Fix OCSP bad key DoS attack CVE-2013-0166
Major changes between OpenSSL 1.0.0i and OpenSSL 1.0.0j [10 May 2012]:
- Fix DTLS record length checking bug CVE-2012-2333
Major changes between OpenSSL 1.0.0h and OpenSSL 1.0.0i [19 Apr 2012]:
- Fix for ASN1 overflow bug CVE-2012-2110
Major changes between OpenSSL 1.0.0g and OpenSSL 1.0.0h [12 Mar 2012]:
- Fix for CMS/PKCS#7 MMA CVE-2012-0884
- Corrected fix for CVE-2011-4619
- Various DTLS fixes.
Major changes between OpenSSL 1.0.0f and OpenSSL 1.0.0g [18 Jan 2012]:
- Fix for DTLS DoS issue CVE-2012-0050
Major changes between OpenSSL 1.0.0e and OpenSSL 1.0.0f [4 Jan 2012]:
- Fix for DTLS plaintext recovery attack CVE-2011-4108
- Clear block padding bytes of SSL 3.0 records CVE-2011-4576
- Only allow one SGC handshake restart for SSL/TLS CVE-2011-4619
- Check parameters are not NULL in GOST ENGINE CVE-2012-0027
Check for malformed RFC3779 data CVE-2011-4577
For more details :
http://www.openssl.org/news/openssl-1.0.0-notes.html
Comments