SCIENTIFIC-LINUX-ERRATA Archives

December 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Connie Sieh <[log in to unmask]>
Reply To:
Date:
Tue, 15 Dec 2015 21:30:59 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (46 lines)
Synopsis:          Moderate: openssl security update
Advisory ID:       SLSA-2015:2617-1
Issue Date:        2015-12-14
CVE Numbers:       CVE-2015-3194
                   CVE-2015-3195
                   CVE-2015-3196
--

A NULL pointer derefernce flaw was found in the way OpenSSL verified
signatures using the RSA PSS algorithm. A remote attacked could possibly
use this flaw to crash a TLS/SSL client using OpenSSL, or a TLS/SSL server
using OpenSSL if it enabled client authentication. (CVE-2015-3194)

A memory leak vulnerability was found in the way OpenSSL parsed PKCS#7 and
CMS data. A remote attacker could use this flaw to cause an application
that parses PKCS#7 or CMS data from untrusted sources to use an excessive
amount of memory and possibly crash. (CVE-2015-3195)

A race condition flaw, leading to a double free, was found in the way
OpenSSL handled pre-shared key (PSK) identify hints. A remote attacker
could use this flaw to crash a multi-threaded SSL/TLS client using
OpenSSL. (CVE-2015-3196)

For the update to take effect, all services linked to the OpenSSL library
must be restarted, or the system rebooted.
--

SL6
  x86_64
    openssl-1.0.1e-42.el6_7.1.i686.rpm
    openssl-1.0.1e-42.el6_7.1.x86_64.rpm
    openssl-debuginfo-1.0.1e-42.el6_7.1.i686.rpm
    openssl-debuginfo-1.0.1e-42.el6_7.1.x86_64.rpm
    openssl-devel-1.0.1e-42.el6_7.1.i686.rpm
    openssl-devel-1.0.1e-42.el6_7.1.x86_64.rpm
    openssl-perl-1.0.1e-42.el6_7.1.x86_64.rpm
    openssl-static-1.0.1e-42.el6_7.1.x86_64.rpm
  i386
    openssl-1.0.1e-42.el6_7.1.i686.rpm
    openssl-debuginfo-1.0.1e-42.el6_7.1.i686.rpm
    openssl-devel-1.0.1e-42.el6_7.1.i686.rpm
    openssl-perl-1.0.1e-42.el6_7.1.i686.rpm
    openssl-static-1.0.1e-42.el6_7.1.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2