--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2016-527018d2ff
2016-01-30 14:54:08.576989
--------------------------------------------------------------------------------

Name        : openssl
Product     : Fedora 23
Version     : 1.0.2f
Release     : 1.fc23
URL         : https://www.openssl.org:443/
Summary     : Utilities from the general purpose cryptography library with TLS implementation
Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.

--------------------------------------------------------------------------------
Update Information:

New upstream version fixing one high serverity and one low severity security
issue.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1301846 - CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers        https://bugzilla.redhat.com/show_bug.cgi?id=1301846
  [ 2 ] Bug #1301845 - CVE-2016-0701 OpenSSL: DH small subgroups
        https://bugzilla.redhat.com/show_bug.cgi?id=1301845
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program. Use
su -c 'yum update openssl' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/

Fedora 23: openssl Security Update

January 30, 2016
New upstream version fixing one high serverity and one low severity security issue.

Summary

The OpenSSL toolkit provides support for secure communications between

machines. OpenSSL includes a certificate management tool and shared

libraries which provide various cryptographic algorithms and

protocols.

Update Information:

New upstream version fixing one high serverity and one low severity security issue.

Change Log

References

[ 1 ] Bug #1301846 - CVE-2015-3197 OpenSSL: SSLv2 doesn't block disabled ciphers https://bugzilla.redhat.com/show_bug.cgi?id=1301846 [ 2 ] Bug #1301845 - CVE-2016-0701 OpenSSL: DH small subgroups https://bugzilla.redhat.com/show_bug.cgi?id=1301845

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update openssl' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : openssl
Product : Fedora 23
Version : 1.0.2f
Release : 1.fc23
URL : https://www.openssl.org:443/
Summary : Utilities from the general purpose cryptography library with TLS implementation

Related News