OVMSA-2015-0029

OVMSA-2015-0029 - openssl security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2015-03-06

Description


[0.9.8e-32.0.1]
- Backport openssl 08-Jan-2015 security fixes (John Haxby) [orabug 20409893]
- fix CVE-2014-3570 - Bignum squaring may produce incorrect results
- fix CVE-2014-3571 - DTLS segmentation fault in dtls1_get_record
- fix CVE-2014-3572 - ECDHE silently downgrades to ECDH [Client]
- fix CVE-2014-8275 - Certificate fingerprints can be modified
- fix CVE-2015-0204 - RSA silently downgrades to EXPORT_RSA [Client]

[0.9.8e-32]
- properly lock X509_STORE accesses (#1168938)


Related CVEs


CVE-2014-3572
CVE-2014-3570
CVE-2014-8275
CVE-2014-3571
CVE-2015-0204

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle VM 2.2 (i386) openssl-0.9.8e-32.0.1.el5_11.src.rpm1227d80ec883d6ef8e6537e1ff1ffb8cbadd9e0597651cdb9750d71445e9378bOVMSA-2023-0013ovm22_i386_latest
openssl-0.9.8e-32.0.1.el5_11.i386.rpmdd82adf2da9bdbcc2080a2c50c1d08e0d15174a6c10f90d5c133b82c5ead27a2OVMSA-2023-0013ovm22_i386_latest
openssl-0.9.8e-32.0.1.el5_11.i686.rpme541e68fd84cf9c005fd37ec3cce976ea2735c675ab22a3ad85526876b6d6b61OVMSA-2023-0013ovm22_i386_latest
Oracle VM 3.2 (x86_64) openssl-0.9.8e-32.0.1.el5_11.src.rpm1227d80ec883d6ef8e6537e1ff1ffb8cbadd9e0597651cdb9750d71445e9378bOVMSA-2023-0013ovm3_3.2.1_x86_64_patch
openssl-0.9.8e-32.0.1.el5_11.i686.rpme541e68fd84cf9c005fd37ec3cce976ea2735c675ab22a3ad85526876b6d6b61OVMSA-2023-0013ovm3_3.2.1_x86_64_patch
openssl-0.9.8e-32.0.1.el5_11.x86_64.rpm7b223713490235a23e4f8efa0d1d564a2a0adb071d993f5cf65fa93033a1ff00OVMSA-2023-0013ovm3_3.2.1_x86_64_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete