Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian DSA-2390-1: OpenSSL Vulnerabilities Exploited via Remote Attacks

debian
Calendar Grey January 15, 2012
Debian Logo
A critical notice regarding multiple OpenSSL vulnerabilities impacting Debian systems, recommending immediate updates to remediate security flaws.
Several vulnerabilities were discovered in OpenSSL, an implementation of TLS and related protocols

Summary

Several vulnerabilities were discovered in OpenSSL, an implementation
of TLS and related protocols. The Common Vulnerabilities and
Exposures project identifies the following vulnerabilities:

CVE-2011-4108
The DTLS implementation performs a MAC check only if certain
padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

CVE-2011-4109
A double free vulnerability when X509_V_FLAG_POLICY_CHECK is
enabled, allows remote attackers to cause applications crashes
and potentially allow execution of arbitrary code by
triggering failure of a policy check.

CVE-2011-4354
On 32-bit systems, the operations on NIST elliptic curves
P-256 and P-384 are not correctly implemented, potentially
leaking the private ECC key of a TLS server. (Regular
RSA-based keys are not affected by this vulnerability.)

CVE-2011-4576
The SSL 3.0 implementation does not properly initialize data
structures for block cipher padding, which might allow remote
attackers to obt...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl
CVE ID: CVE-2011-4108 CVE-2011-4109 CVE-2011-4354

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here