Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 582020

Summary: dev-libs/libressl-2.2.6: 2.2.7 available fixing several vulnerabilities
Product: Gentoo Security Reporter: Török Edwin <edwin+bugs>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED OBSOLETE    
Severity: normal CC: dashmz
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.2.7-relnotes.txt
Whiteboard:
Package list:
Runtime testing required: ---

Description Török Edwin 2016-05-03 21:20:15 UTC
LibreSSL 2.2.7 is available, please update the ebuild.


Reproducible: Always

Steps to Reproduce:
1. Run 'openssl version'
2. Check http://www.libressl.org/releases.html for latest release number
Actual Results:  
LibreSSL 2.2.6

Expected Results:  
LibreSSL 2.2.7

See http://marc.info/?l=openbsd-announce&m=146228598930416&w=2 and the release notes in this bug's URL.
LibreSSL 2.2.7/2.3.4 seems to be the equivalent for the vulnerability fixes in OpenSSL 1.0.2h (although I don't know why libressl.org still says March 22, the releases page says May 3).
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-07-06 12:42:30 UTC
Package is unstable and newer versions are already in the tree.