1
0
Fork 1
mirror of https://github.com/NixOS/nixpkgs.git synced 2025-01-22 14:45:27 +00:00
nixpkgs/pkgs/development
Martin Weinelt bb4f46855f openssl: 1.1.1f → 1.1.1g
Fixes: CVE-2020-1967

Segmentation fault in SSL_check_chain (CVE-2020-1967)
=====================================================

Severity: High

Server or client applications that call the SSL_check_chain() function during or
after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a
result of incorrect handling of the "signature_algorithms_cert" TLS extension.
The crash occurs if an invalid or unrecognised signature algorithm is received
from the peer. This could be exploited by a malicious peer in a Denial of
Service attack.

OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue.  This
issue did not affect OpenSSL versions prior to 1.1.1d.

Affected OpenSSL 1.1.1 users should upgrade to 1.1.1g

This issue was found by Bernd Edlinger and reported to OpenSSL on 7th April
2020. It was found using the new static analysis pass being implemented in GCC,
- -fanalyzer. Additional analysis was performed by Matt Caswell and Benjamin
Kaduk.
2020-04-22 02:14:44 +02:00
..
androidndk-pkgs
arduino Merge pull request #84190 from geistesk/platformio-4.3.1 2020-04-17 11:37:07 +01:00
beam-modules
bower-modules/generic
chez-modules
compilers Merge master into staging-next 2020-04-21 19:59:56 +02:00
coq-modules coqPackages.dpdgraph: fix build with OCaml ≥ 4.08 2020-04-13 11:04:26 +02:00
dhall-modules
dotnet-modules/patches
em-modules/generic
go-modules
go-packages
guile-modules
haskell-modules treewide: per RFC45, remove more unquoted URLs 2020-04-18 14:04:37 +02:00
idris-modules
interpreters Merge master into staging-next 2020-04-21 19:59:56 +02:00
java-modules
libraries openssl: 1.1.1f → 1.1.1g 2020-04-22 02:14:44 +02:00
lisp-modules
lua-modules
misc Merge pull request #84551 from gnprice/pr-stripDebugList 2020-04-14 15:54:52 +02:00
mobile
node-packages treewide: per RFC45, remove more unquoted URLs 2020-04-18 14:04:37 +02:00
ocaml-modules Merge pull request #85636 from matthewbauer/blas-lapack-fix-fallout-from-83888 2020-04-21 19:59:16 +02:00
perl-modules Merge branch 'staging-next' into staging 2020-04-13 18:54:59 +02:00
pharo
pure-modules
python-modules Merge master into staging-next 2020-04-21 19:59:56 +02:00
r-modules treewide: use blas and lapack 2020-04-17 16:24:09 -05:00
ruby-modules
tools Merge master into staging-next 2020-04-21 19:59:56 +02:00
web nodejs-13_x: 13.12.0 -> 13.13.0 2020-04-14 18:00:00 -05:00