[Bug 1304042] [NEW] CVE-2014-0160

king_kilr alex.gaynor at gmail.com
Mon Apr 7 21:22:59 UTC 2014


*** This bug is a security vulnerability ***

Public security bug reported:

The version of OpenSSL which is shipped with Ubuntu is vulnerable to
CVE-2014-0160. This is resolved with OpenSSL 1.0.1g
(https://www.openssl.org/news/secadv_20140407.txt). This is *extremely*
high severity, see heartbleed.com for full information.

** Affects: openssl (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to openssl in Ubuntu.
https://bugs.launchpad.net/bugs/1304042

Title:
  CVE-2014-0160

Status in “openssl” package in Ubuntu:
  New

Bug description:
  The version of OpenSSL which is shipped with Ubuntu is vulnerable to
  CVE-2014-0160. This is resolved with OpenSSL 1.0.1g
  (https://www.openssl.org/news/secadv_20140407.txt). This is
  *extremely* high severity, see heartbleed.com for full information.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1304042/+subscriptions



More information about the foundations-bugs mailing list