ELSA-2018-4077

ELSA-2018-4077 - openssl security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2018-04-18

Description


[1.0.2k-12.0.1]
- sha256 is used for the RSA pairwise consistency test instead of sha1

[1.0.2k-12]
- fix CVE-2017-3737 - incorrect handling of fatal error state
- fix CVE-2017-3738 - AVX2 Montgomery multiplication bug with 1024 bit modulus

[1.0.2k-11]
- fix deadlock in RNG in the FIPS mode in mariadb

[1.0.2k-9]
- fix CVE-2017-3736 - carry propagation bug in Montgomery multiplication


Related CVEs



Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) openssl-1.0.2k-12.0.1.ksplice1.el7.src.rpm03ca8157726a5a4a7824fd8f03ba586d1c32812f8f20a5bb5dbf9f64f9ea029cELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm51702a9e17e464f2010be40701258d4a1b729b02f71c80b73ea3b4c165db7051ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-devel-1.0.2k-12.0.1.ksplice1.el7.i686.rpm9a3dcd0e300cd02551a0ca9b5693dbb4e2016d44d991405f1f887e520ae42f79ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-devel-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm3a1facdf034d490c0c8fed45237dce1ab261045244b936d37497cbef92f26cc1ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-libs-1.0.2k-12.0.1.ksplice1.el7.i686.rpmf5f975055d761102728b5f9500ec60175aec3cf36d9e989d495f20055490f765ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-libs-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpmf3b87d3eb4e8395c63a0187c7e87043904cb1f6841c5af9f52056116a405f0b5ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-perl-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm11eebb7463779fbdc77c7a476dc546512c9e9cda22eb324ebcfa6f821eba710eELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-static-1.0.2k-12.0.1.ksplice1.el7.i686.rpm034482826f254dd88b8d9d3c07842b9fa96c9802eaeedf2b606fd8e054cfd06aELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-static-1.0.2k-12.0.1.ksplice1.el7.x86_64.rpm86dabdbe93389a9d0bca4438025f95f7c1e2ca951399cccb50eec2b813277c5cELSA-2017-3518ol7_x86_64_userspace_ksplice



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete