Oracle Errata System
Oracle Linux
5.3
2021-09-09T12:48:18
ELSA-2016-3556: openssl security update (IMPORTANT)
Oracle Linux 7
[1.0.1e-51.5]
- fix CVE-2016-2105 - possible overflow in base64 encoding
- fix CVE-2016-2106 - possible overflow in EVP_EncryptUpdate()
- fix CVE-2016-2107 - padding oracle in stitched AES-NI CBC-MAC
- fix CVE-2016-2108 - memory corruption in ASN.1 encoder
- fix CVE-2016-2109 - possible DoS when reading ASN.1 data from BIO
- fix CVE-2016-0799 - memory issues in BIO_printf
[1.0.1e-51.4]
- fix CVE-2016-0702 - side channel attack on modular exponentiation
- fix CVE-2016-0705 - double-free in DSA private key parsing
- fix CVE-2016-0797 - heap corruption in BN_hex2bn and BN_dec2bn
[1.0.1e-51.3]
- fix CVE-2015-3197 - SSLv2 ciphersuite enforcement
- disable SSLv2 in the generic TLS method
[1.0.1e-51.2]
- fix CVE-2015-7575 - disallow use of MD5 in TLS1.2
[1.0.1e-51.1]
- fix CVE-2015-3194 - certificate verify crash with missing PSS parameter
- fix CVE-2015-3195 - X509_ATTRIBUTE memory leak
- fix CVE-2015-3196 - race condition when handling PSK identity hint
IMPORTANT
Copyright 2016 Oracle, Inc.
CVE-2016-0799
CVE-2016-2105
CVE-2016-2107
CVE-2016-2842
CVE-2016-2106
CVE-2016-2108
CVE-2016-2109
oraclelinux-release
openssl
openssl-devel
openssl-perl
openssl-static
openssl-libs
72f97b74ec551f03
ksplice
^7
x86_64
2:1.0.1e-51.ksplice1.el7_2.5