Bug 254551 - security/openssl: Update to 1.1.1k (Security Update - High)
Summary: security/openssl: Update to 1.1.1k (Security Update - High)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Bernard Spil
URL: https://www.openssl.org/news/vulnerab...
Keywords: security
Depends on:
Blocks:
 
Reported: 2021-03-25 14:17 UTC by Pascal Christen
Modified: 2021-03-26 08:40 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (brnrd)


Attachments
patch (679 bytes, patch)
2021-03-25 14:17 UTC, Pascal Christen
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Pascal Christen 2021-03-25 14:17:21 UTC
Created attachment 223573 [details]
patch

Update to OpenSSL 1.1.1k

https://www.openssl.org/news/openssl-1.1.1-notes.html
Comment 1 Bernard Spil freebsd_committer freebsd_triage 2021-03-25 16:18:53 UTC
Working on it!
Comment 2 Pascal Christen 2021-03-26 06:28:23 UTC
A simple POC to create a DOS is really easy and already public. So would be nice if you can share that update to the public ;)
Comment 3 commit-hook freebsd_committer freebsd_triage 2021-03-26 08:13:17 UTC
A commit references this bug:

Author: brnrd
Date: Fri Mar 26 08:13:04 UTC 2021
New revision: 569247
URL: https://svnweb.freebsd.org/changeset/ports/569247

Log:
  security/openssl: Security update to 1.1.1k

  PR:		254551
  Submitted by:	Pascal Christen <pascal christen hostpoint ch>
  MFH:		2021Q1
  Security:	5a668ab3-8d86-11eb-b8d6-d4c9ef517024

Changes:
  head/security/openssl/Makefile
  head/security/openssl/distinfo
Comment 4 commit-hook freebsd_committer freebsd_triage 2021-03-26 08:16:18 UTC
A commit references this bug:

Author: brnrd
Date: Fri Mar 26 08:15:42 UTC 2021
New revision: 569248
URL: https://svnweb.freebsd.org/changeset/ports/569248

Log:
  MFH: r569247

  security/openssl: Security update to 1.1.1k

  PR:		254551
  Submitted by:	Pascal Christen <pascal christen hostpoint ch>
  Security:	5a668ab3-8d86-11eb-b8d6-d4c9ef517024

  Approved by:	ports-secteam (blanket)

Changes:
_U  branches/2021Q1/
  branches/2021Q1/security/openssl/Makefile
  branches/2021Q1/security/openssl/distinfo
Comment 5 Bernard Spil freebsd_committer freebsd_triage 2021-03-26 08:18:30 UTC
(In reply to Pascal Christen from comment #2)
Not denying that, but here's more parts to updating this than just your patch...

vuxml entry must be created
make test
run poudriere testport on all versions
gpg verify tarball

And next to that, there's also a payed job that requires attention
Comment 6 Pascal Christen 2021-03-26 08:40:13 UTC
(In reply to Bernard Spil from comment #5)

Yes, sorry. I didn't want to annoy you at all. I know everyone is doing their best and spending free time. I really appreciate that!