Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Debian: DSA-2908-1 Critical OpenSSL Use-After-Free and ECDSA Issues

debian
Calendar Grey April 17, 2014
Scroller Debian
Explore recent patches for OpenSSL on Debian platforms. Mitigate severe threats and maintain system reliability.
Multiple vulnerabilities have been discovered in OpenSSL

Summary

Multiple vulnerabilities have been discovered in OpenSSL. The following
Common Vulnerabilities and Exposures project ids identify them:

CVE-2010-5298

A read buffer can be freed even when it still contains data that is
used later on, leading to a use-after-free. Given a race condition in a
multi-threaded application it may permit an attacker to inject data from
one connection into another or cause denial of service.

CVE-2014-0076

ECDSA nonces can be recovered through the Yarom/Benger FLUSH+RELOAD
cache side-channel attack.

A third issue, with no CVE id, is the missing detection of the
"critical" flag for the TSA extended key usage under certain cases.


Additionally, this update checks for more services that might need to
be restarted after upgrades of libssl, corrects the detection of
apache2 and postgresql, and adds support for the
'libraries/restart-without-asking' debconf configuration. This allows
services to be restarted on upgrade without prompting.


The oldstable distribution (squeeze) i...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl
CVE ID: CVE-2010-5298 CVE-2014-0076

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.