ELSA-2019-4754

ELSA-2019-4754 - openssl security update

Type:SECURITY
Impact:MODERATE
Release Date:2019-08-19

Description


[1.0.2k-19.0.1]
- Bump release for rebuild.

[1.0.2k-19]
- close the RSA decryption 9 lives of Bleichenbacher cat
timing side channel (#1649568)

[1.0.2k-18]
- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)

[1.0.2k-17]
- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
timing side-channel key extraction


Related CVEs



Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) openssl-1.0.2k-19.0.1.ksplice1.el7.src.rpmce1ba908ed240247f45088979f2639ddcb04dba81e4ee0acece42c6ae4b9e4a2ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm7da2024278f1983daf84823448ff476448c10cba30bf62dc8839260038e316a4ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-devel-1.0.2k-19.0.1.ksplice1.el7.i686.rpma6db7ecab08945ac4d0b387e4ba9dc397574dbf24d437c82cb37c32a113d62a4ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-devel-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm4dc84762c51e88dbe363ab52e13e27bb6848d8796d31d0e8171e28ce56a57964ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-libs-1.0.2k-19.0.1.ksplice1.el7.i686.rpmcffd590c6b6c8838570de84ba73ee188271283917dd20e031ac9dfc65efdd53bELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-libs-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm510b589eea4f57241cd052a8de1cc24253ad4136e3b3c887c0e842d0025847a4ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-perl-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm7aadca28126a355540a8a670ed9ec9cb276935a3a45b95d86e3ccd8528c799caELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-static-1.0.2k-19.0.1.ksplice1.el7.i686.rpm8f4625b5ddde6aa231f0414c4038c009d531f731a06b2632960f8ff7f4a26082ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-static-1.0.2k-19.0.1.ksplice1.el7.x86_64.rpm0aff35412ae235492944ce45f469aab68a59d176a5e31cbd738f5f9492636c26ELSA-2017-3518ol7_x86_64_userspace_ksplice



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete