Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

Fedora 22: 2015-10047 Moderate Update on OpenSSL Security Issues

fedora
Calendar Grey June 21, 2015
Scroller Fedora
A series of important and minor vulnerabilities addressed in Fedora 22's OpenSSL package. Discover more details about the security enhancements!
Multiple moderate and low impact security issues fixed.

Summary

The OpenSSL toolkit provides support for secure communications between

machines. OpenSSL includes a certificate management tool and shared

libraries which provide various cryptographic algorithms and

protocols.

Update Information:

Multiple moderate and low impact security issues fixed.

Change Log

* Mon Jun 15 2015 Tomáš Mráz 1.0.1k-10 - fix CVE-2015-1789 - out-of-bounds read in X509_cmp_time - fix CVE-2015-1790 - PKCS7 crash with missing EncryptedContent - fix CVE-2015-1791 - race condition handling NewSessionTicket - fix CVE-2015-1792 - CMS verify infinite loop with unknown hash function - add missing parts of CVE-2015-0209 fix for corectness although unexploitable * Fri May 29 2015 Tomáš Mráz 1.0.1k-9 - fix CVE-2015-4000 - prevent the logjam attack on client - restrict the DH key size to at least 768 bits (limit will be increased in future)

References


[ 1 ] Bug #1228603 - CVE-2015-1789 OpenSSL: out-of-bounds read in X509_cmp_time https://bugzilla.redhat.com/show_bug.cgi?id=1228603 [ 2 ] Bug #1228604 - CVE-2015-1790 OpenSSL: PKCS7 crash with missing EnvelopedContent https://bugzilla.redhat.com/show_bug.cgi?id=1228604 [ 3 ] Bug #1228607 - CVE-2015-1792 OpenSSL: CMS verify infinite loop with unknown hash function https://bugzilla.redhat.com/show_bug.cgi?id=1228607 [ 4 ] Bug #1228608 - CVE-2015-1791 OpenSSL: Race condition handling NewSessionTicket https://bugzilla.redhat.com/show_bug.cgi?id=1228608

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update openssl' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: openssl
Product: Fedora 22
Version: 1.0.1k
Release: 10.fc22
Summary: Utilities from the general purpose cryptography library with TLS implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.