Skip to content

Conversation

@rvagg
Copy link
Member

@rvagg rvagg commented Jun 15, 2018

Backport of #21282 but for OpenSSL 1.0.2
See also #21343 for 8.x

I'm not sure what 6.x lts label this should get, if any, so help would be appreciated.

Pending OpenSSL 1.0.2p release.

Ref: https://github.com/nodejs/node/pull/21282
Reviewed-By: Shigeki Ohtsu <ohtsu@ohtsu.org>
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Upstream: https://github.com/openssl/openssl/commit/3984ef0

Original commit message:
    Reject excessively large primes in DH key generation.

    CVE-2018-0732

    Signed-off-by: Guido Vranken <guidovranken@gmail.com>

    (cherry picked from commit 91f7361)

    Reviewed-by: Tim Hudson <tjh@openssl.org>
    Reviewed-by: Matt Caswell <matt@openssl.org>
    (Merged from #6457)

Pending OpenSSL 1.0.2p release.

Ref: nodejs#21282
Reviewed-By: Shigeki Ohtsu <ohtsu@ohtsu.org>
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Upstream: openssl/openssl@3984ef0

Original commit message:
    Reject excessively large primes in DH key generation.

    CVE-2018-0732

    Signed-off-by: Guido Vranken <guidovranken@gmail.com>

    (cherry picked from commit 91f7361)

    Reviewed-by: Tim Hudson <tjh@openssl.org>
    Reviewed-by: Matt Caswell <matt@openssl.org>
    (Merged from nodejs#6457)
@nodejs-github-bot
Copy link
Collaborator

@nodejs-github-bot nodejs-github-bot added openssl Issues and PRs related to the OpenSSL dependency. v6.x labels Jun 15, 2018
@refack
Copy link
Contributor

refack commented Jun 15, 2018

@rvagg
Copy link
Member Author

rvagg commented Jun 18, 2018

5a30e0b

@rvagg rvagg closed this Jun 18, 2018
@rvagg rvagg deleted the rvagg/openssl-3984ef0-v6.x branch June 18, 2018 04:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

openssl Issues and PRs related to the OpenSSL dependency.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants