From 7d266d26c56a76af57cd24e064472bf8dbf33156c9637f0985ef7560007ec037 Mon Sep 17 00:00:00 2001 From: Jason Sikes Date: Sun, 18 Apr 2021 23:41:13 +0000 Subject: [PATCH] Accepting request 886496 from home:jsikes:branches:security:tls Added bsc numbers to changelog. OBS-URL: https://build.opensuse.org/request/show/886496 OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-1_1?expand=0&rev=92 --- openssl-1_1.changes | 2 ++ 1 file changed, 2 insertions(+) diff --git a/openssl-1_1.changes b/openssl-1_1.changes index e80d2a2..8b2b8a7 100644 --- a/openssl-1_1.changes +++ b/openssl-1_1.changes @@ -6,6 +6,7 @@ Thu Mar 25 23:51:47 UTC 2021 - Jason Sikes the X509_V_FLAG_X509_STRICT flag. This flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. ([CVE-2021-3450]) + [bsc#1183851] * Fixed an issue where an OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a @@ -18,6 +19,7 @@ Thu Mar 25 23:51:47 UTC 2021 - Jason Sikes A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. ([CVE-2021-3449]) + [bsc#1183852] ------------------------------------------------------------------- Tue Mar 2 19:40:25 UTC 2021 - Pedro Monreal