openssl: security bump to version 1.0.2g
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 1 Mar 2016 14:38:36 +0000 (11:38 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 1 Mar 2016 14:48:08 +0000 (15:48 +0100)
commit25b218c144805a4fcd100396a936bc7bdccdedbc
tree31bbfe7d59295135fe725d230625a952a3e8caad
parenta6209d1b9759cd58fb2df17d2098b644cba9ca25
openssl: security bump to version 1.0.2g

Fixes:
CVE-2016-0800 - Cross-protocol attack on TLS using SSLv2 (DROWN)
CVE-2016-0705 - Double-free in DSA code
CVE-2016-0798 - Memory leak in SRP database lookups
CVE-2016-0797 - BN_hex2bn/BN_dec2bn NULL pointer deref/heap corruption
CVE-2016-0799 - Fix memory issues in BIO_*printf functions
CVE-2016-0702 - Side channel attack on modular exponentiation

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/openssl/openssl.hash
package/openssl/openssl.mk