Fedora Update Notification
FEDORA-2004-095
2004-03-19
---------------------------------------------------------------------

Name        : openssl
Version     : 0.9.7a                      
Release     : 33.10                  
Summary     : The OpenSSL toolkit.
Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.

---------------------------------------------------------------------
Update Information:

This update includes OpenSSL packages to fix two security issues
affecting OpenSSL 0.9.7a which allow denial of service attacks; CVE
CAN-2004-0079 and CVE CAN-2003-0851.

Also included are updates for the OpenSSL 0.9.6 and 0.9.6b
compatibility libraries included in Fedora Core 1, fixing a separate
issue which could also lead to a denial of service attack; CVE
CAN-2004-0081.

---------------------------------------------------------------------
This update can be downloaded from:
   
e8bdb97523942f9ffaa2266557522cb4  SRPMS/openssl-0.9.7a-33.10.src.rpm
e8b8fa33866d3bfb18a0bb363b7da157  i386/openssl-0.9.7a-33.10.i386.rpm
185ce2fa3dcc7eefd08755fbf32ba4b9  i386/openssl-devel-0.9.7a-33.10.i386.rpm
dffeec7a90d6d455d42f4150f8d87234  i386/openssl-perl-0.9.7a-33.10.i386.rpm
910b24732d051afceda9f9c725b26eaf  i386/debug/openssl-debuginfo-0.9.7a-33.10.i386.rpm
f2c1ee5973157103d6699fb8122a42cd  i386/openssl-0.9.7a-33.10.i686.rpm
aae58c51061b47c4886249787a6b0d12  i386/debug/openssl-debuginfo-0.9.7a-33.10.i686.rpm
ef901bfd90760a5a9bfe04964fc1edaf  x86_64/openssl-0.9.7a-33.10.x86_64.rpm
0efb65591070daa52274aeba71c27c25  x86_64/openssl-devel-0.9.7a-33.10.x86_64.rpm
6c37c57523dafe0125ea7cafd9d03bd1  x86_64/openssl-perl-0.9.7a-33.10.x86_64.rpm
e3fa109733cd72647c96cd02a2c92628  x86_64/debug/openssl-debuginfo-0.9.7a-33.10.x86_64.rpm

bfa1844b85a37b4985bc05078c34dc5a  SRPMS/openssl096-0.9.6-26.src.rpm
a138ec3378572805b3607f0e55eb081a  i386/openssl096-0.9.6-26.i386.rpm
810ef6df3fcc5762b3b69654f9f1e145  i386/debug/openssl096-debuginfo-0.9.6-26.i386.rpm
b54014864a487e940b0a433755e75893  x86_64/openssl096-0.9.6-26.x86_64.rpm
12c3ebe731dc15263ae8e980173c3f9f  x86_64/debug/openssl096-debuginfo-0.9.6-26.x86_64.rpm

216c598e2d8ded8f24f1c3b828051743  SRPMS/openssl096b-0.9.6b-18.src.rpm
5db375e1acdaf84a33ccab3f9f48b171  i386/openssl096b-0.9.6b-18.i386.rpm
b904fa03ff1b6ad06a488e3388b74a58  i386/debug/openssl096b-debuginfo-0.9.6b-18.i386.rpm
d2f6313c15f893b15230a82bc9ca5c5e  x86_64/openssl096b-0.9.6b-18.x86_64.rpm
25804bd47caad8bb6a6d74f46c36cf62  x86_64/debug/openssl096b-debuginfo-0.9.6b-18.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.

Fedora: OpenSSL Denial of service vulnerabilities

March 23, 2004
This update includes OpenSSL packages to fix two security issues affecting OpenSSL 0.9.7a which allow denial of service attacks.

Summary

The OpenSSL toolkit provides support for secure communications between

machines. OpenSSL includes a certificate management tool and shared

libraries which provide various cryptographic algorithms and

protocols.

Update Information:

This update includes OpenSSL packages to fix two security issues affecting OpenSSL 0.9.7a which allow denial of service attacks; CVE CAN-2004-0079 and CVE CAN-2003-0851.

Also included are updates for the OpenSSL 0.9.6 and 0.9.6b compatibility libraries included in Fedora Core 1, fixing a separate issue which could also lead to a denial of service attack; CVE CAN-2004-0081.

This update can be downloaded from:

e8bdb97523942f9ffaa2266557522cb4 SRPMS/openssl-0.9.7a-33.10.src.rpm e8b8fa33866d3bfb18a0bb363b7da157 i386/openssl-0.9.7a-33.10.i386.rpm 185ce2fa3dcc7eefd08755fbf32ba4b9 i386/openssl-devel-0.9.7a-33.10.i386.rpm dffeec7a90d6d455d42f4150f8d87234 i386/openssl-perl-0.9.7a-33.10.i386.rpm 910b24732d051afceda9f9c725b26eaf i386/debug/openssl-debuginfo-0.9.7a-33.10.i386.rpm f2c1ee5973157103d6699fb8122a42cd i386/openssl-0.9.7a-33.10.i686.rpm aae58c51061b47c4886249787a6b0d12 i386/debug/openssl-debuginfo-0.9.7a-33.10.i686.rpm ef901bfd90760a5a9bfe04964fc1edaf x86_64/openssl-0.9.7a-33.10.x86_64.rpm 0efb65591070daa52274aeba71c27c25 x86_64/openssl-devel-0.9.7a-33.10.x86_64.rpm 6c37c57523dafe0125ea7cafd9d03bd1 x86_64/openssl-perl-0.9.7a-33.10.x86_64.rpm e3fa109733cd72647c96cd02a2c92628 x86_64/debug/openssl-debuginfo-0.9.7a-33.10.x86_64.rpm

bfa1844b85a37b4985bc05078c34dc5a SRPMS/openssl096-0.9.6-26.src.rpm a138ec3378572805b3607f0e55eb081a i386/openssl096-0.9.6-26.i386.rpm 810ef6df3fcc5762b3b69654f9f1e145 i386/debug/openssl096-debuginfo-0.9.6-26.i386.rpm b54014864a487e940b0a433755e75893 x86_64/openssl096-0.9.6-26.x86_64.rpm 12c3ebe731dc15263ae8e980173c3f9f x86_64/debug/openssl096-debuginfo-0.9.6-26.x86_64.rpm

216c598e2d8ded8f24f1c3b828051743 SRPMS/openssl096b-0.9.6b-18.src.rpm 5db375e1acdaf84a33ccab3f9f48b171 i386/openssl096b-0.9.6b-18.i386.rpm b904fa03ff1b6ad06a488e3388b74a58 i386/debug/openssl096b-debuginfo-0.9.6b-18.i386.rpm d2f6313c15f893b15230a82bc9ca5c5e x86_64/openssl096b-0.9.6b-18.x86_64.rpm 25804bd47caad8bb6a6d74f46c36cf62 x86_64/debug/openssl096b-debuginfo-0.9.6b-18.x86_64.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Change Log

References

Fedora Update Notification FEDORA-2004-095 2004-03-19 Name : openssl Version : 0.9.7a Release : 33.10 Summary : The OpenSSL toolkit. Description : The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols.

Update Instructions

Severity
Name : openssl
Version : 0.9.7a
Release : 33.10
Summary : The OpenSSL toolkit.

Related News