File tree Expand file tree Collapse file tree 9 files changed +21
-17
lines changed
Misc/NEWS.d/next/Security Expand file tree Collapse file tree 9 files changed +21
-17
lines changed Original file line number Diff line number Diff line change 5757 variables :
5858 testRunTitle : ' $(build.sourceBranchName)-linux'
5959 testRunPlatform : linux
60- openssl_version : 1.1.1q
60+ openssl_version : 1.1.1t
6161
6262 steps :
6363 - template : ./posix-steps.yml
8383 variables :
8484 testRunTitle : ' $(Build.SourceBranchName)-linux-coverage'
8585 testRunPlatform : linux-coverage
86- openssl_version : 1.1.1q
86+ openssl_version : 1.1.1t
8787
8888 steps :
8989 - template : ./posix-steps.yml
Original file line number Diff line number Diff line change 5757 variables :
5858 testRunTitle : ' $(system.pullRequest.TargetBranch)-linux'
5959 testRunPlatform : linux
60- openssl_version : 1.1.1q
60+ openssl_version : 1.1.1t
6161
6262 steps :
6363 - template : ./posix-steps.yml
8383 variables :
8484 testRunTitle : ' $(Build.SourceBranchName)-linux-coverage'
8585 testRunPlatform : linux-coverage
86- openssl_version : 1.1.1q
86+ openssl_version : 1.1.1t
8787
8888 steps :
8989 - template : ./posix-steps.yml
Original file line number Diff line number Diff line change @@ -176,7 +176,7 @@ jobs:
176176 needs : check_source
177177 if : needs.check_source.outputs.run_tests == 'true'
178178 env :
179- OPENSSL_VER : 1.1.1s
179+ OPENSSL_VER : 1.1.1t
180180 PYTHONSTRICTEXTENSIONBUILD : 1
181181 steps :
182182 - uses : actions/checkout@v3
@@ -235,7 +235,7 @@ jobs:
235235 strategy :
236236 fail-fast : false
237237 matrix :
238- openssl_ver : [1.1.1s , 3.0.7 , 3.1.0-beta1]
238+ openssl_ver : [1.1.1t , 3.0.8 , 3.1.0-beta1]
239239 env :
240240 OPENSSL_VER : ${{ matrix.openssl_ver }}
241241 MULTISSL_DIR : ${{ github.workspace }}/multissl
@@ -282,7 +282,7 @@ jobs:
282282 needs : check_source
283283 if : needs.check_source.outputs.run_tests == 'true'
284284 env :
285- OPENSSL_VER : 1.1.1s
285+ OPENSSL_VER : 1.1.1t
286286 PYTHONSTRICTEXTENSIONBUILD : 1
287287 ASAN_OPTIONS : detect_leaks=0:allocator_may_return_null=1:handle_segv=0
288288 steps :
Original file line number Diff line number Diff line change @@ -246,9 +246,9 @@ def library_recipes():
246246
247247 result .extend ([
248248 dict (
249- name = "OpenSSL 1.1.1s " ,
250- url = "https://www.openssl.org/source/openssl-1.1.1s .tar.gz" ,
251- checksum = 'c5ac01e760ee6ff0dab61d6b2bbd30146724d063eb322180c6f18a6f74e4b6aa ' ,
249+ name = "OpenSSL 1.1.1t " ,
250+ url = "https://www.openssl.org/source/openssl-1.1.1t .tar.gz" ,
251+ checksum = '8dee9b24bdb1dcbf0c3d1e9b02fb8f6bf22165e807f45adeb7c9677536859d3b ' ,
252252 buildrecipe = build_universal_openssl ,
253253 configure = None ,
254254 install = None ,
Original file line number Diff line number Diff line change 1+ Updated the OpenSSL version used in Windows and macOS binary release builds
2+ to 1.1.1t to address CVE-2023-0286, CVE-2022-4303, and CVE-2022-4303 per
3+ `the OpenSSL 2023-02-07 security advisory
4+ <https://www.openssl.org/news/secadv/20230207.txt> `_.
Original file line number Diff line number Diff line change @@ -53,7 +53,7 @@ echo.Fetching external libraries...
5353set libraries =
5454set libraries = %libraries% bzip2-1.0.8
5555if NOT " %IncludeLibffiSrc% " == " false" set libraries = %libraries% libffi-3.4.3
56- if NOT " %IncludeSSLSrc% " == " false" set libraries = %libraries% openssl-1.1.1s
56+ if NOT " %IncludeSSLSrc% " == " false" set libraries = %libraries% openssl-1.1.1t
5757set libraries = %libraries% sqlite-3.39.4.0
5858if NOT " %IncludeTkinterSrc% " == " false" set libraries = %libraries% tcl-core-8.6.13.0
5959if NOT " %IncludeTkinterSrc% " == " false" set libraries = %libraries% tk-8.6.13.0
@@ -77,7 +77,7 @@ echo.Fetching external binaries...
7777
7878set binaries =
7979if NOT " %IncludeLibffi% " == " false" set binaries = %binaries% libffi-3.4.3
80- if NOT " %IncludeSSL% " == " false" set binaries = %binaries% openssl-bin-1.1.1s
80+ if NOT " %IncludeSSL% " == " false" set binaries = %binaries% openssl-bin-1.1.1t
8181if NOT " %IncludeTkinter% " == " false" set binaries = %binaries% tcltk-8.6.13.0
8282if NOT " %IncludeSSLSrc% " == " false" set binaries = %binaries% nasm-2.11.06
8383
Original file line number Diff line number Diff line change 7474 <libffiDir Condition =" $(libffiDir) == ''" >$(ExternalsDir)libffi-3.4.3\</libffiDir >
7575 <libffiOutDir Condition =" $(libffiOutDir) == ''" >$(libffiDir)$(ArchName)\</libffiOutDir >
7676 <libffiIncludeDir Condition =" $(libffiIncludeDir) == ''" >$(libffiOutDir)include</libffiIncludeDir >
77- <opensslDir Condition =" $(opensslDir) == ''" >$(ExternalsDir)openssl-1.1.1s \</opensslDir >
78- <opensslOutDir Condition =" $(opensslOutDir) == ''" >$(ExternalsDir)openssl-bin-1.1.1s \$(ArchName)\</opensslOutDir >
77+ <opensslDir Condition =" $(opensslDir) == ''" >$(ExternalsDir)openssl-1.1.1t \</opensslDir >
78+ <opensslOutDir Condition =" $(opensslOutDir) == ''" >$(ExternalsDir)openssl-bin-1.1.1t \$(ArchName)\</opensslOutDir >
7979 <opensslIncludeDir Condition =" $(opensslIncludeDir) == ''" >$(opensslOutDir)include</opensslIncludeDir >
8080 <nasmDir Condition =" $(nasmDir) == ''" >$(ExternalsDir)\nasm-2.11.06\</nasmDir >
8181 <zlibDir Condition =" $(zlibDir) == ''" >$(ExternalsDir)\zlib-1.2.13\</zlibDir >
Original file line number Diff line number Diff line change @@ -169,7 +169,7 @@ _lzma
169169 Homepage:
170170 https://tukaani.org/xz/
171171_ssl
172- Python wrapper for version 1.1.1q of the OpenSSL secure sockets
172+ Python wrapper for version 1.1.1t of the OpenSSL secure sockets
173173 library, which is downloaded from our binaries repository at
174174 https://github.com/python/cpython-bin-deps.
175175
Original file line number Diff line number Diff line change 4646]
4747
4848OPENSSL_RECENT_VERSIONS = [
49- "1.1.1s " ,
50- "3.0.7 "
49+ "1.1.1t " ,
50+ "3.0.8 "
5151]
5252
5353LIBRESSL_OLD_VERSIONS = [
You can’t perform that action at this time.
0 commit comments