HomePhabricator

gitian: upgrade OpenSSL to 1.0.1h
6e7c4d17d8abUnpublished

Unpublished Commit ยท Learn More

Repository Importing: This repository is still importing.

Description

gitian: upgrade OpenSSL to 1.0.1h

Upgrade for https://www.openssl.org/news/secadv_20140605.txt

Just in case - there is no vulnerability that affects ecdsa signing or
verification.

The MITM attack vulnerability (CVE-2014-0224) may have some effect on
our usage of SSL/TLS.

As long as payment requests are signed (which is the common case), usage
of the payment protocol should also not be affected.

The TLS usage in RPC may be at risk for MITM attacks. If you have
-rpcssl enabled, be sure to update OpenSSL as soon as possible.

Details

Provenance
Wladimir J. van der Laan <laanwj@gmail.com>Authored on Jun 5 2014, 13:44
deadalnixPushed on May 14 2017, 22:04
Parents
rABCa92aded70ec2: Fix GUI build with `--disable-wallet`
Branches
Unknown
Tags
Unknown

Event Timeline

Wladimir J. van der Laan <laanwj@gmail.com> committed rABC6e7c4d17d8ab: gitian: upgrade OpenSSL to 1.0.1h (authored by Wladimir J. van der Laan <laanwj@gmail.com>).Jun 5 2014, 15:24