DSA-1888-1

NameDSA-1888-1
SourceDebian
Descriptionopenssl - cryptographic weakness
ReferencesCVE-2009-2409
Debian/oldstablepackages openssl, openssl097 are fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssl (PTS)etch0.9.8c-4etch4vulnerable
etch (security)0.9.8c-4etch9fixed
lenny, lenny (security)0.9.8g-15+lenny6fixed
openssl097 (PTS)etch0.9.7k-3.1etch2vulnerable
etch (security)0.9.7k-3.1etch5fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
libssl-dev, libssl0.9.8, libssl0.9.8-dbg, openssletch0.9.8c-4etch4vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)0.9.8c-4etch9fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
lenny, lenny (security)0.9.8g-15+lenny6fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
libssl0.9.7, libssl0.9.7-dbgetch0.9.7k-3.1etch2vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)0.9.7k-3.1etch5fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensslsourceetch0.9.8c-4etch9unknown
opensslsourcelenny0.9.8g-15+lenny5unknown
openssl097sourceetch0.9.7k-3.1etch5unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint