IPFire 2.19 - Core Update 102 released
The IPFire Project
ipfire-announce at lists.ipfire.org
Wed May 4 21:57:02 CEST 2016
This is the official release announcement for IPFire 2.19 – Core Update 102.
This update contains various security fixes in the OpenSSL library. It is
recommended to install this update as soon as possible.
OpenSSL Security Fixes
The OpenSSL team published fixes for several security issues  yesterday:
* Memory corruption in the ASN.1 encoder (CVE-2016-2108)
* Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
* EVP_EncodeUpdate overflow (CVE-2016-2105)
* EVP_EncryptUpdate overflow (CVE-2016-2106)
* ASN.1 BIO excessive memory allocation (CVE-2016-2109)
* EBCDIC overread (CVE-2016-2176)
This Core Update brings you OpenSSL 1.0.2h which fixes all of these above.
Additionally OpenSSH is updated to version 7.2p2 and will be restarted during
We are currently crowdfunding a Captive Portal for IPFire  and would like you
to ask to check it out and support us!
Please help us to support the work on IPFire Project with your donation .
More information about the IPFire-Announce