All of lore.kernel.org
 help / color / mirror / Atom feed
* OpenBMC CVE issues in openssl
@ 2019-09-24  2:25 Wang, Kuiying
  2019-09-24  2:41 ` Brad Bishop
  0 siblings, 1 reply; 8+ messages in thread
From: Wang, Kuiying @ 2019-09-24  2:25 UTC (permalink / raw)
  To: openbmc; +Cc: Xu, Qiang, Jia, Chunhui, Brad Bishop, Mihm, James, Shi, Yilei

[-- Attachment #1: Type: text/plain, Size: 709 bytes --]

Hi Brad,
Openssl is already upgrade to 1.1.1d, so please help sync to the latest version.
https://github.com/openembedded/openembedded-core/tree/master/meta/recipes-connectivity/openssl

Please let me know, if you need me to submit patch for this upgrading.

Thanks,
Kwin.

> Hi,
>
> Some openssl vulnerabilities are found by security scan on latest OpenBMC
> which is using openssl 1.1.1c
>
> CVE-2019-1549
> CVE-2019-1563
> CVE-2019-1547
>
> They are fixed in latest openssl version 1.1.1d.
>
> Do we have plan to upgrade openssl recently?
>
> Thanks

I don't think 1.1.1d has landed upstream yet.  If you update oe-core to
1.1.1d I will pick it up once it lands there.

-brad


[-- Attachment #2: Type: text/html, Size: 5864 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2020-05-08  0:28 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-09-24  2:25 OpenBMC CVE issues in openssl Wang, Kuiying
2019-09-24  2:41 ` Brad Bishop
2019-09-24  2:48   ` Wang, Kuiying
2019-09-24 11:11     ` Brad Bishop
2019-09-25  1:22       ` Wang, Kuiying
2020-05-07  7:43   ` openssl upgrade chunhui.jia
2020-05-07 16:54     ` openssl upgrade CVE-2020-1967 Joseph Reynolds
2020-05-08  0:27       ` chunhui.jia

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.