ELSA-2016-3523

ELSA-2016-3523 - openssl security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2016-03-01

Description


[1.0.1e-51.4]
- fix CVE-2016-0702 - side channel attack on modular exponentiation
- fix CVE-2016-0705 - double-free in DSA private key parsing
- fix CVE-2016-0797 - heap corruption in BN_hex2bn and BN_dec2bn

[1.0.1e-51.3]
- fix CVE-2015-3197 - SSLv2 ciphersuite enforcement
- disable SSLv2 in the generic TLS method

[1.0.1e-51.2]
- fix CVE-2015-7575 - disallow use of MD5 in TLS1.2

[1.0.1e-51.1]
- fix CVE-2015-3194 - certificate verify crash with missing PSS parameter
- fix CVE-2015-3195 - X509_ATTRIBUTE memory leak
- fix CVE-2015-3196 - race condition when handling PSK identity hint


Related CVEs



Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 6 (x86_64) openssl-1.0.1e-42.ksplice1.el6_7.4.src.rpm91f55d338f1b3789d7e087babae300c36713f451fa925fd2e8ac6a2042f2db56ELSA-2023-12326ol6_x86_64_userspace_ksplice
openssl-1.0.1e-42.ksplice1.el6_7.4.i686.rpm79e8b55029a1e3f832afc79c2db4629733a3fc427f1e7b91021083f0000cd5d2ELSA-2023-12326ol6_x86_64_userspace_ksplice
openssl-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpma5fba0a47dd905fe831eb98a9b65fd433287eca380076912563a2bca0bcd730aELSA-2023-12326ol6_x86_64_userspace_ksplice
openssl-devel-1.0.1e-42.ksplice1.el6_7.4.i686.rpm83e5226d8ee3553f0f78faecb1702e3eb89b90f81c5843037da2d39485674123ELSA-2023-12326ol6_x86_64_userspace_ksplice
openssl-devel-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpm6581651930ee5ce3e8c6929bc65c34a6063d9c3c3df7b97676479e64a171e0aaELSA-2023-12326ol6_x86_64_userspace_ksplice
openssl-perl-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpm33207b8d3983393fe3b282e76d903b55f25431e345d0d40ed048d1e72116f6ffELSA-2023-12326ol6_x86_64_userspace_ksplice
openssl-static-1.0.1e-42.ksplice1.el6_7.4.x86_64.rpmccd07fa8ab2daae163a416ec22cc1af888bcca5899ddadac2a25c86f409c882bELSA-2023-12326ol6_x86_64_userspace_ksplice
Oracle Linux 7 (x86_64) openssl-1.0.1e-51.ksplice1.el7_2.4.src.rpm43093146a87d946509df42f289b89fc46cca5a4a707af8f0d58caa89c59c5e6cELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpm64f270f28ead5bebf80a0dcc5307da6b29270a321851665422018d8d5b6ace6aELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-devel-1.0.1e-51.ksplice1.el7_2.4.i686.rpm5214057cba821da7cd7a72ed91765f647f7c1259669463ab4e95e565d9065f22ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-devel-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpmce33d861ed4308fa020424516d2526714b10ea20360bcf277f3647679a62a4d0ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-libs-1.0.1e-51.ksplice1.el7_2.4.i686.rpm1fb6715d526bce1a34d101e83b61c5fad5d7ba5e0879d01192ae91124fd1ff57ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-libs-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpmbece3be0df9325bf3be5874055a642a42790f0e52f64ae62b5d127ba471f2fe6ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-perl-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpm75b09940f6ff3f90e98eb7e4431633828fd73a32cb0931ec4768e2ca9d6b9633ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-static-1.0.1e-51.ksplice1.el7_2.4.i686.rpm6a4dd238659204923a9db10f80ca909991429b110cb0a0778eb34d05eebff063ELSA-2017-3518ol7_x86_64_userspace_ksplice
openssl-static-1.0.1e-51.ksplice1.el7_2.4.x86_64.rpm4af74fc63499e3cd96e2c1dd3326951298bed84d39d94a4a7974bf961249f83bELSA-2017-3518ol7_x86_64_userspace_ksplice



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete