[OE-core] [PATCH] openssl: fix for CVE-2015-1794

Alexander Kanavin alexander.kanavin at linux.intel.com
Wed Dec 9 13:33:11 UTC 2015


On 12/09/2015 01:52 PM, Burton, Ross wrote:

> This patch needs to have your (or whoever actually did the work)
> signed-off-by inside the patch, alongside the Upstream-Status.

Also, it's been fixed in openssl 1.0.2e with a bunch of other CVEs - 
I'll send an update for that shortly.

Generally, for oe-core master we always prefer an update to latest 
upstream instead of adding backported patches.

Alex



More information about the Openembedded-core mailing list