[openssl-dev] backporting CVE-2016-8610 fix to 1.0.1 branch

Peter Djalaliev (CS) Peter_Djalaliev at symantec.com
Sat Dec 17 01:59:00 UTC 2016


Hello,

Will commit

Don't allow too many consecutive warning alerts

author   Matt Caswell <matt at openssl.org>
                Wed, 21 Sep 2016 08:07:31 -0500 (14:07 +0100)
committer            Matt Caswell <matt at openssl.org>
                Wed, 21 Sep 2016 14:17:04 -0500 (20:17 +0100)
commit  af58be768ebb690f78530f796e92b8ae5c9a4401
tree        087701bd731382d1933438bcd73cb7029264e16b
parent   7dc0ad4d6dca81a003be7fa1fbd58a55f4be8646

be backported to 1.0.1? This has been assigned CVE-2016-8610. I understand that OpenSSL 1.0.1 is going EOL on Dec 31.

Thank you,
Peter Djalaliev

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20161217/1990bee5/attachment-0001.html>


More information about the openssl-dev mailing list