Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 12.04: USN-1500-1 Major OpenSSL Security Flaw Detected

ubuntu
Calendar Grey February 9, 2012
Scroller Ubuntu
Ubuntu Security Notice USN-1357-1 highlights severe OpenSSL issues affecting multiple releases, updates needed.
Multiple vulnerabilities exist in OpenSSL that could exposesensitive information or cause applications to crash.

Summary

Multiple vulnerabilities exist in OpenSSL that could expose

sensitive information or cause applications to crash.

Software Description:

- openssl: Secure Socket Layer (SSL) binary and related cryptographic tools

Details:

It was discovered that the elliptic curve cryptography (ECC) subsystem

in OpenSSL, when using the Elliptic Curve Digital Signature Algorithm

(ECDSA) for the ECDHE_ECDSA cipher suite, did not properly implement

curves over binary fields. This could allow an attacker to determine

private keys via a timing attack. This issue only affected Ubuntu 8.04

LTS, Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-1945)

Adam Langley discovered that the ephemeral Elliptic Curve

Diffie-Hellman (ECDH) functionality in OpenSSL did not ensure thread

safety while processing handshake messages from clients. This

could allow a remote attacker to cause a denial of service via

out-of-order messages that violate the TLS protocol. This issue only

affected Ubuntu 8.04 LTS, Ubun...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libssl1.0.0                     1.0.0e-2ubuntu4.2
  openssl                         1.0.0e-2ubuntu4.2

Ubuntu 11.04:
  libssl0.9.8                     0.9.8o-5ubuntu1.2
  openssl                         0.9.8o-5ubuntu1.2

Ubuntu 10.10:
  libssl0.9.8                     0.9.8o-1ubuntu4.6
  openssl                         0.9.8o-1ubuntu4.6

Ubuntu 10.04 LTS:
  libssl0.9.8                     0.9.8k-7ubuntu8.8
  openssl                         0.9.8k-7ubuntu8.8

Ubuntu 8.04 LTS:
  libssl0.9.8                     0.9.8g-4ubuntu3.15
  openssl                         0.9.8g-4ubuntu3.15

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

CVE-2011-1945, CVE-2011-3210, CVE-2011-4108, CVE-2011-4109,

CVE-2011-4354, CVE-2011-4576, CVE-2011-4577, CVE-2011-4619,

CVE-2012-0027, CVE-2012-0050

Severity
critical
Lowest
Low
Medium
High
Critical

February 09, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.