SCIENTIFIC-LINUX-ERRATA Archives

May 2016

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 31 May 2016 16:26:36 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (36 lines)
Synopsis:          Important: openssl security update
Advisory ID:       SLSA-2016:1137-1
Issue Date:        2016-05-31
CVE Numbers:       CVE-2016-2108
--

Security Fix(es):

* A flaw was found in the way OpenSSL encoded certain ASN.1 data
structures. An attacker could use this flaw to create a specially crafted
certificate which, when verified or re-encoded by OpenSSL, could cause it
to crash, or execute arbitrary code using the permissions of the user
running an application compiled against the OpenSSL library.
(CVE-2016-2108)
--

SL5
  x86_64
    openssl-0.9.8e-40.el5_11.i686.rpm
    openssl-0.9.8e-40.el5_11.x86_64.rpm
    openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm
    openssl-debuginfo-0.9.8e-40.el5_11.x86_64.rpm
    openssl-perl-0.9.8e-40.el5_11.x86_64.rpm
    openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm
    openssl-devel-0.9.8e-40.el5_11.i386.rpm
    openssl-devel-0.9.8e-40.el5_11.x86_64.rpm
  i386
    openssl-0.9.8e-40.el5_11.i386.rpm
    openssl-0.9.8e-40.el5_11.i686.rpm
    openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm
    openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm
    openssl-perl-0.9.8e-40.el5_11.i386.rpm
    openssl-devel-0.9.8e-40.el5_11.i386.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2