ELSA-2016-3523

ELSA-2016-3523 - openssl security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2016-03-01

Description


[1.0.1e-51.4]
- fix CVE-2016-0702 - side channel attack on modular exponentiation
- fix CVE-2016-0705 - double-free in DSA private key parsing
- fix CVE-2016-0797 - heap corruption in BN_hex2bn and BN_dec2bn

[1.0.1e-51.3]
- fix CVE-2015-3197 - SSLv2 ciphersuite enforcement
- disable SSLv2 in the generic TLS method

[1.0.1e-51.2]
- fix CVE-2015-7575 - disallow use of MD5 in TLS1.2

[1.0.1e-51.1]
- fix CVE-2015-3194 - certificate verify crash with missing PSS parameter
- fix CVE-2015-3195 - X509_ATTRIBUTE memory leak
- fix CVE-2015-3196 - race condition when handling PSK identity hint


Related CVEs



Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (x86_64) openssl-1.0.1e-42.ksplice1.el6_7.4.src.rpmaa81e7991d726bab0e10d680c6977e42ELSA-2021-9150
openssl-1.0.1e-42.ksplice1.el6_7.4.i686.rpm675202135239150911a0a471f4423932ELSA-2021-9150
openssl-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpm2b68582d4af094764dd6e33f99022881ELSA-2021-9150
openssl-devel-1.0.1e-42.ksplice1.el6_7.4.i686.rpm9fda81d360783204e9dcd9fbf34c8832ELSA-2021-9150
openssl-devel-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpm0fe4eb34608032995ca25e4c333c176aELSA-2021-9150
openssl-perl-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpme3112ac9c5dfe1150b28dc6148ee90b9ELSA-2021-9150
openssl-static-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpmb1dab3bb89395f8b01d3d1e9f4e39ab3ELSA-2021-9150
Oracle Linux 7 (x86_64) openssl-1.0.1e-51.ksplice1.el7_2.4.src.rpmdef27052c6eac0b0c747a998a089667dELSA-2017-3518
openssl-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpm199cd4a9ee5a127d54ca8048738b3defELSA-2017-3518
openssl-devel-1.0.1e-51.ksplice1.el7_2.4.i686.rpmd7c9c8cffff3e9c40fb37d1c24adab7fELSA-2017-3518
openssl-devel-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpm0dcbb3fe10ee4c3b1d917950e56becbcELSA-2017-3518
openssl-libs-1.0.1e-51.ksplice1.el7_2.4.i686.rpm02beac2f8c7f74edee3ffdf3c24f173fELSA-2017-3518
openssl-libs-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpmfd226d1593d1cdc7f6137a99a813d1c7ELSA-2017-3518
openssl-perl-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpmff440f182d8b1b90ed608a3f67618a45ELSA-2017-3518
openssl-static-1.0.1e-51.ksplice1.el7_2.4.i686.rpm9de37fca5017bc97fd4e4d12cfe745e4ELSA-2017-3518
openssl-static-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpmecb2452dc01810e88198ab2788129136ELSA-2017-3518



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete