Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: NixOS/nixpkgs
base: dabf3f8a0b8a
Choose a base ref
...
head repository: NixOS/nixpkgs
compare: f7f742f9fb29
Choose a head ref
  • 2 commits
  • 1 file changed
  • 2 contributors

Commits on Apr 22, 2020

  1. openssl: 1.1.1f → 1.1.1g

    Fixes: CVE-2020-1967
    
    Segmentation fault in SSL_check_chain (CVE-2020-1967)
    =====================================================
    
    Severity: High
    
    Server or client applications that call the SSL_check_chain() function during or
    after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a
    result of incorrect handling of the "signature_algorithms_cert" TLS extension.
    The crash occurs if an invalid or unrecognised signature algorithm is received
    from the peer. This could be exploited by a malicious peer in a Denial of
    Service attack.
    
    OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue.  This
    issue did not affect OpenSSL versions prior to 1.1.1d.
    
    Affected OpenSSL 1.1.1 users should upgrade to 1.1.1g
    
    This issue was found by Bernd Edlinger and reported to OpenSSL on 7th April
    2020. It was found using the new static analysis pass being implemented in GCC,
    - -fanalyzer. Additional analysis was performed by Matt Caswell and Benjamin
    Kaduk.
    mweinelt committed Apr 22, 2020
    Configuration menu
    Copy the full SHA
    bb4f468 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #85732 from mweinelt/openssl1.1.1g

    openssl: 1.1.1f → 1.1.1g
    worldofpeace committed Apr 22, 2020
    Configuration menu
    Copy the full SHA
    f7f742f View commit details
    Browse the repository at this point in the history