guix-commits
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

01/02: gnu: address@hidden: Replace with 1.0.2m [fixes CVE-2017-3735, CV


From: Marius Bakke
Subject: 01/02: gnu: address@hidden: Replace with 1.0.2m [fixes CVE-2017-3735, CVE-2017-2736].
Date: Thu, 2 Nov 2017 17:22:34 -0400 (EDT)

mbakke pushed a commit to branch master
in repository guix.

commit 1df4f5c919937b60bfb21ac2a60d8f0a6737c421
Author: Marius Bakke <address@hidden>
Date:   Thu Nov 2 22:11:25 2017 +0100

    gnu: address@hidden: Replace with 1.0.2m [fixes CVE-2017-3735, 
CVE-2017-2736].
    
    * gnu/packages/tls.scm (openssl)[replacement]: New field.
    (openssl-1.0.2m): New public variable.
---
 gnu/packages/tls.scm | 20 ++++++++++++++++++++
 1 file changed, 20 insertions(+)

diff --git a/gnu/packages/tls.scm b/gnu/packages/tls.scm
index 075ea7a..7611d4e 100644
--- a/gnu/packages/tls.scm
+++ b/gnu/packages/tls.scm
@@ -245,6 +245,7 @@ required structures.")
   (package
    (name "openssl")
    (version "1.0.2l")
+   (replacement openssl-1.0.2m)
    (source (origin
              (method url-fetch)
              (uri (list (string-append "ftp://ftp.openssl.org/source/";
@@ -387,6 +388,25 @@ required structures.")
    (license license:openssl)
    (home-page "http://www.openssl.org/";)))
 
+;; Fixes CVE-2017-3735 and CVE-2017-3736.
+;; See <https://www.openssl.org/news/cl102.txt>.
+(define-public openssl-1.0.2m
+  (package
+    (inherit openssl)
+    (version "1.0.2m")
+    (source (origin
+              (inherit (package-source openssl))
+              (uri (list (string-append 
"https://www.openssl.org/source/openssl-";
+                                        version ".tar.gz")
+                         (string-append "ftp://ftp.openssl.org/source/openssl-";
+                                        version ".tar.gz")
+                         (string-append "ftp://ftp.openssl.org/source/old/";
+                                        (string-trim-right version 
char-set:letter)
+                                        "/openssl-" version ".tar.gz")))
+              (sha256
+               (base32
+                "03vvlfnxx4lhxc83ikfdl6jqph4h52y7lb7li03va6dkqrgg2vwc"))))))
+
 (define-public openssl-next
   (package
     (inherit openssl)



reply via email to

[Prev in Thread] Current Thread [Next in Thread]