ELSA-2019-4754

ELSA-2019-4754 - openssl security update

Type:SECURITY
Severity:MODERATE
Release Date:2019-08-19

Description


[1.0.2k-19.0.1]
- Bump release for rebuild.

[1.0.2k-19]
- close the RSA decryption 9 lives of Bleichenbacher cat
timing side channel (#1649568)

[1.0.2k-18]
- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)

[1.0.2k-17]
- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
timing side-channel key extraction


Related CVEs



Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) openssl-1.0.2k-19.0.1.ksplice1.el7.src.rpm1e7b283a27d06255bb5f2ff3e76f6a51ELSA-2017-3518
openssl-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpmde0c9087cebc22dde38ecfb5f6c9316eELSA-2017-3518
openssl-devel-1.0.2k-19.0.1.ksplice1.el7.i686.rpm0b0cf0148168dfa01bcf1885d23f510eELSA-2017-3518
openssl-devel-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm3d541a937844cc4532036746c9e07bbcELSA-2017-3518
openssl-libs-1.0.2k-19.0.1.ksplice1.el7.i686.rpmae978aadced8f16eb2e28b4acfb32ebdELSA-2017-3518
openssl-libs-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm9bac5fa5210b56adf69388aa27304abaELSA-2017-3518
openssl-perl-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm4687cca6f4987f3df79b3358577dfee2ELSA-2017-3518
openssl-static-1.0.2k-19.0.1.ksplice1.el7.i686.rpmafdd7b363e28a5b572c713fcfe1bd098ELSA-2017-3518
openssl-static-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpmd1958d2feb1a805c34ec80695a03bbb4ELSA-2017-3518



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete