Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Oracle Linux 5 ELSA-2016-1137 Critical: OpenSSL Memory Corruption

oracle
Calendar Grey May 31, 2016
Oracle Linux Logo Esm H88
Important Oracle Linux security patch ELSA-2016-1137 addressing multiple vulnerabilities in OpenSSL. Access key information here.
The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network:

Summary

[0.9.8e-40.0.1] - To disable SSLv2 client connections create the file /etc/sysconfig/openssl-ssl-client-kill-sslv2 (John Haxby) [orabug 21673934] - Backport openssl 08-Jan-2015 security fixes (John Haxby) [orabug 20409893] - fix CVE-2014-3570 - Bignum squaring may produce incorrect results - fix CVE-2014-3571 - DTLS segmentation fault in dtls1_get_record - fix CVE-2014-3572 - ECDHE silently downgrades to ECDH [Client] [0.9.8e-40] - fix CVE-2016-2108 - memory corruption in ASN.1 encoder

SRPMs

https://oss.oracle.com:443/ol5/SRPMS-updates/openssl-0.9.8e-40.0.1.el5_11.src.rpm

x86_64

openssl-0.9.8e-40.0.1.el5_11.i686.rpm openssl-0.9.8e-40.0.1.el5_11.x86_64.rpm openssl-devel-0.9.8e-40.0.1.el5_11.i386.rpm openssl-devel-0.9.8e-40.0.1.el5_11.x86_64.rpm openssl-perl-0.9.8e-40.0.1.el5_11.x86_64.rpm ia64: openssl-0.9.8e-40.0.1.el5_11.i686.rpm openssl-0.9.8e-40.0.1.el5_11.ia64.rpm openssl-devel-0.9.8e-40.0.1.el5_11.ia64.rpm openssl-perl-0.9.8e-40.0.1.el5_11.ia64.rpm

aarch64

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here