All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mark Evans <mark.a.evans@gmail.com>
To: Khem Raj <raj.khem@gmail.com>
Cc: Yocto Project <yocto@yoctoproject.org>
Subject: Re: OpenSSL 1.0.0m
Date: Thu, 24 Jul 2014 20:46:11 -0500	[thread overview]
Message-ID: <53D1B6E3.4070002@gmail.com> (raw)
In-Reply-To: <CAMKF1srrntvZoe6b_mUq2i0tC=GGSFX3GV3UhQ96V9MAv5aF7A@mail.gmail.com>

Thanks for the nfo. I'll go there and take a look.
--MarkE

On 7/24/2014 7:51 PM, Khem Raj wrote:
> On Thu, Jul 24, 2014 at 5:44 PM, Mark Evans <mark.a.evans@gmail.com> wrote:
>> question on the openssl recipes and openssl versions... Point me to the
>> correct distro if this is the incorrect spot to ask this...
>>
>> We're currently on Danny, 1.3.2. In there, the openssl version is 1.0.0j.
>> The openssl project is currently promoting  1.0.1h. Due to the multiple CVEs
>> being released, we're wanting to move to the latest. But, looking at the
>> poky releases, it seems that, after "Danny", Poky reverted back to 1.0.0e
>> and added patches as CVEs are released. For example, here's the patches in
>> "Daisy" (1.6.1):
>>
>> openssl-1.0.1e-cve-2014-0195.patch
>> openssl-1.0.1e-cve-2014-0198.patch
>> openssl-1.0.1e-cve-2014-0221.patch
>> openssl-1.0.1e-cve-2014-0224.patch
>> openssl-1.0.1e-cve-2014-3470.patch
>> openssl-CVE-2010-5298.patch
>>
>> Am I reading that correct? If I move to the recipes there, will that close
>> current issues on openssl? Or, is there a recipe available to use 1.0.1h?
>>
> oe-core/master is having 1.0.1h, you can backport that into your own
> layer and tool your project
> to use it.
>
>
>> Thanks for any info.
>> Mark Evans
>>
>> --
>> _______________________________________________
>> yocto mailing list
>> yocto@yoctoproject.org
>> https://lists.yoctoproject.org/listinfo/yocto
>>



  reply	other threads:[~2014-07-25  1:46 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-07-24 20:45 Why won't my app use multiple threads under 'valleyisland'? Chris Tapp
2014-07-25  0:44 ` OpenSSL 1.0.0m Mark Evans
2014-07-25  0:51   ` Khem Raj
2014-07-25  1:46     ` Mark Evans [this message]
2014-07-29 15:41 ` [meta-intel] Why won't my app use multiple threads under 'valleyisland'? Darren Hart
2014-07-30 22:14   ` Chris Tapp

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=53D1B6E3.4070002@gmail.com \
    --to=mark.a.evans@gmail.com \
    --cc=raj.khem@gmail.com \
    --cc=yocto@yoctoproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.