ELSA-2018-4077

ELSA-2018-4077 - openssl security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2018-04-18

Description


[1.0.2k-12.0.1]
- sha256 is used for the RSA pairwise consistency test instead of sha1

[1.0.2k-12]
- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulus

[1.0.2k-11]
- fix deadlock in RNG in the FIPS mode in mariadb

[1.0.2k-9]
- fix CVE-2017-3736 - carry propagation bug in Montgomery multiplication


Related CVEs



Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) openssl-1.0.2k-12.0.1.ksplice1.el7.src.rpm7430a8898bf364f060bb7a0aa3cdf3eaELSA-2017-3518
openssl-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm7135e64e2ebb5dab7d0e17ba062b4117ELSA-2017-3518
openssl-devel-1.0.2k-12.0.1.ksplice1.el7.i686.rpmeaba49ae98f4a183328d1de034034b52ELSA-2017-3518
openssl-devel-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpma3d66112ad6b9093d6c07b1b4b69f210ELSA-2017-3518
openssl-libs-1.0.2k-12.0.1.ksplice1.el7.i686.rpmbdf8537b1a96d5d189a752d7420548aaELSA-2017-3518
openssl-libs-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm1b775f296be2bcd826936606603dc9a5ELSA-2017-3518
openssl-perl-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm1cb0eeb78edfd6be8724a8d95df37800ELSA-2017-3518
openssl-static-1.0.2k-12.0.1.ksplice1.el7.i686.rpm5baf6d9175b25327693130bc295bda0eELSA-2017-3518
openssl-static-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpmb7c1ea061d991315ff1cdc568778261aELSA-2017-3518



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete