Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA-3287-1 Critical: OpenSSL Remote Denial Of Service

debian
Calendar Grey June 13, 2015
Debian Logo
Critical OpenSSL flaws discovered; users advised to upgrade their Debian installations to maintain system protection.
Multiple vulnerabilities were discovered in OpenSSL, a Secure Sockets Layer toolkit

Summary

CVE-2014-8176

Praveen Kariyanahalli, Ivan Fratric and Felix Groebert discovered
that an invalid memory free could be triggered when buffering DTLS
data. This could allow remote attackers to cause a denial of service
(crash) or potentially execute arbitrary code. This issue only
affected the oldstable distribution (wheezy).

CVE-2015-1788

Joseph Barr-Pixton discovered that an infinite loop could be triggered
due to incorrect handling of malformed ECParameters structures. This
could allow remote attackers to cause a denial of service.

CVE-2015-1789

Robert Swiecki and Hanno Böck discovered that the X509_cmp_time
function could read a few bytes out of bounds. This could allow remote
attackers to cause a denial of service (crash) via crafted
certificates and CRLs.

CVE-2015-1790

Michal Zalewski discovered that the PKCS#7 parsing code did not
properly handle missing content which could lead to a NULL pointer
dereference. This could allow remote a...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl
CVE ID: CVE-2014-8176 CVE-2015-1788 CVE-2015-1789 CVE-2015-1790

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here