LWN.net Logo

Fedora alert FEDORA-2009-0543 (tqsllib)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 9 Update: tqsllib-2.0-5.fc9
Date:  Thu, 15 Jan 2009 03:07:29 +0000
Message-ID:  <20090115030729.387A188046@bastion.fedora.phx.redhat.com>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-0543 2009-01-14 23:38:30 -------------------------------------------------------------------------------- Name : tqsllib Product : Fedora 9 Version : 2.0 Release : 5.fc9 URL : http://sourceforge.net/projects/trustedqsl/ Summary : The TrustedQSL library Description : The TrustedQSL library is used for generating digitally signed QSO records (records of Amateur Radio contacts). This package contains the library and configuration files needed to run TrustedQSL applications. -------------------------------------------------------------------------------- Update Information: The TrustedQSL library incorrectly checked the result after calling the EVP_VerifyFinal function, allowing a malformed signature to be treated as a good signature rather than as an error. Package includes a patch to fix EVP_VerifyFinal result check. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 12 2009 Lucian Langa <cooly@gnome.eu.org> - 2.0-5 - modify patch0 to include fix for #479650 (CVE-2008-5077 related) -------------------------------------------------------------------------------- References: [ 1 ] Bug #479650 - tqsllib: OpenSSL incorrect checks for malformed signatures https://bugzilla.redhat.com/show_bug.cgi?id=479650 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update tqsllib' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds