Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 6 MGASA-2018-0365 Moderate: OpenSSL Denial Of Service Threat

mageia
Calendar Grey September 2, 2018
Dist Mageia Esm H88
MGASA-2018-0365 - Updated openssl packages fix security vulnerabilities Publication date: 02 Sep 201
Updated openssl packages fix security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value...

Summary

Updated openssl packages fix security vulnerabilities:
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack (CVE-2018-0732).
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key (CVE-2018-0737).

References

- https://bugs.mageia.org/show_bug.cgi?id=22934

- https://openssl-library.org/news/secadv/20180416.txt

- https://openwall.com/lists/oss-security/2018/04/16/3

- https://ubuntu.com/security/notices/USN-3692-1

- https://ubuntu.com/security/notices/USN-3628-1

- https://www.cve.org/CVERecord?id=CVE-2018-0732

- https://www.cve.org/CVERecord?id=CVE-2018-0737

Resolution

SRPMS

- 6/core/openssl-1.0.2p-1.mga6

Publication date: 02 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0365.html
Type: security
CVE: CVE-2018-0732, CVE-2018-0737

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here