Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-8275

Published: 8 January 2015

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.

Priority

Low

Status

Package Release Status
openssl
Launchpad, Ubuntu, Debian
artful
Released (1.0.1f-1ubuntu10)
bionic
Released (1.0.1f-1ubuntu10)
cosmic
Released (1.0.1f-1ubuntu10)
disco
Released (1.0.1f-1ubuntu10)
lucid
Released (0.9.8k-7ubuntu8.23)
precise
Released (1.0.1-4ubuntu5.21)
trusty
Released (1.0.1f-1ubuntu2.8)
upstream
Released (0.9.8zd, 1.0.1k)
utopic
Released (1.0.1f-1ubuntu9.1)
vivid
Released (1.0.1f-1ubuntu10)
wily
Released (1.0.1f-1ubuntu10)
xenial
Released (1.0.1f-1ubuntu10)
yakkety
Released (1.0.1f-1ubuntu10)
zesty
Released (1.0.1f-1ubuntu10)
Patches:
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=86edf13b1c97526c0cf63c37342aaa01f5442688
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=5951cc004b96cd681ffdf39d3fc9238a1ff597ae
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=a8565530e27718760220df469f0a071c85b9e731
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=178c562a4621162dbe19a7c34fa2ad558684f40e
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=7fae32f6d69baf27ef69d92499c59c8a3277f3e3
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=c22e2dd6e52899926d1f1ee3a2b5b9570d03130f
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=63f3c9e715955f0cdc83698d8a3dfb1b80064407
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=ec2fede9467ae1a65f452d3a39f7fbc4891d9285
upstream: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=11f719da38c5e9aa509aa518d11f71355cca7cd1
openssl098
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

cosmic Does not exist

disco Does not exist

lucid Does not exist

precise Ignored
(end of life)
trusty Does not exist
(trusty was needed)
upstream
Released (0.9.8zd, 1.0.1k)
utopic Ignored
(end of life)
vivid Ignored
(end of life)
wily Does not exist

xenial Does not exist

yakkety Does not exist

zesty Does not exist