GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Dec 03, 2013 6:26 am Post subject: [ GLSA 201312-03 ] OpenSSL: Multiple Vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: OpenSSL: Multiple Vulnerabilities (GLSA 201312-03)
Severity: low
Exploitable: remote
Date: December 03, 2013
Updated: July 07, 2014
Bug(s): #369753, #406199, #412643, #415435, #455592
ID: 201312-03
Synopsis
Multiple vulnerabilities have been found in OpenSSL allowing remote
attackers to determine private keys or cause a Denial of Service.
Background
OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
(SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general
purpose cryptography library.
Affected Packages
Package: dev-libs/openssl
Vulnerable: < 1.0.0j
Vulnerable: < 0.9.8y
Unaffected: >= 1.0.0j
Unaffected: >= 0.9.8y < 0.9.9
Unaffected: >= 0.9.8z_p1 < 0.9.9
Unaffected: >= 0.9.8z_p2 < 0.9.9
Unaffected: >= 0.9.8z_p3 < 0.9.9
Unaffected: >= 0.9.8z_p4 < 0.9.9
Unaffected: >= 0.9.8z_p5 < 0.9.9
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in OpenSSL. Please review
the CVE identifiers referenced below for details.
Impact
Remote attackers can determine private keys, decrypt data, cause a
Denial of Service or possibly have other unspecified impact.
Workaround
There is no known workaround at this time.
Resolution
All OpenSSL 1.0.x users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.0.0j"
| All OpenSSL 0.9.8 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.8y"
|
References
CVE-2006-7250
CVE-2011-1945
CVE-2012-0884
CVE-2012-1165
CVE-2012-2110
CVE-2012-2333
CVE-2012-2686
CVE-2013-0166
CVE-2013-0169
Last edited by GLSA on Tue Jul 08, 2014 4:31 am; edited 2 times in total |
|