CVE-2009-3245 not fixed for 8.04LTS
Bug #655884 reported by
rfoster55
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openssl (Ubuntu) |
Fix Released
|
Low
|
Unassigned | ||
Dapper |
Fix Released
|
Low
|
Unassigned | ||
Hardy |
Fix Released
|
Low
|
Unassigned | ||
Jaunty |
Fix Released
|
Low
|
Unassigned | ||
Karmic |
Fix Released
|
Low
|
Unassigned |
Bug Description
Binary package hint: openssl
When trying to make our server PCI compliant I found that the latest openssl package 0.9.8g-4ubuntu3.x hasn't been updated to address CVE-2009-3245. This is surprising since it has been fixed and released in Debian stable so I wonder if this is just an oversight here.
"OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/
Can we get these changes into the 8.04LTS openssl packages? Thanks.
visibility: | private → public |
To post a comment you must log in.
Thanks for reporting this issue. This isn't an oversight, this CVE is correctly being tracked in our CVE tracker:
http:// people. canonical. com/~ubuntu- security/ cve/2009/ CVE-2009- 3245.html
Since we consider this to be a "low" priority issue, it will be bundled in a future openssl security update.