来自:https://marc.info/?l=openbsd-announce&m=140752800525709
公告:
We have released LibreSSL 2.0.5, which should be arriving in the
LibreSSL directory of an OpenBSD mirror near you.
This version forward-ports security fixes from OpenSSL 1.0.1i,
including fixes for the following CVEs:
CVE-2014-3506
CVE-2014-3507
CVE-2014-3508 (partially vulnerable)
CVE-2014-3509
CVE-2014-3510
CVE-2014-3511
LibreSSL 2.0.4 was not found vulnerable to the following CVEs:
CVE-2014-5139
CVE-2014-3512
CVE-2014-3505
We welcome feedback and support from the community as we
continue to work on LibreSSL.
Thank you,
Brent我们的问题是:为什么LibreSSL没有受到CVE-2014-5139,CVE-2014-3512,CVE-2014-3505的影响,并且只部分易受影响: CVE-2014-3508?谁能简单地解释一下吗?
OpenSSL安全咨询链接:https://www.openssl.org/news/secadv_20140806.txt
发布于 2014-08-17 01:47:33
注意:我将CVEs链接到Redhat的Bugzilla,因为它们总是链接到实际的提交者修复问题,这很好。
https://security.stackexchange.com/questions/65537
复制相似问题