[Secure-testing-team] Bug#770229: CVE-2014-2901 CVE-2014-2902 CVE-2014-2903 CVE-2014-2904

Moritz Muehlenhoff jmm at debian.org
Wed Nov 19 22:17:43 UTC 2014


Source: cyassl
Severity: grave
Tags: security

Please see https://marc.info/?l=oss-security&m=139779940032403&w=2

On a related note:
I noticed that mysql/mariadb hasn't switched to using cyassl. Without
any rev deps we should rather avoid including it in jessie IMO and
base on cyassl for jessie+1.

Cheers,
        Moritz

-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.16-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash



More information about the Secure-testing-team mailing list