Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 12.10 USN-1732-1 Critical: OpenSSL Denial Of Service Threats Fixed

ubuntu
Calendar Grey February 21, 2013
Scroller Ubuntu
=========================================================================Ubuntu Security Notice USN-
Several security issues were fixed in OpenSSL.

Summary

Several security issues were fixed in OpenSSL.

Software Description:

- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Adam Langley and Wolfgang Ettlingers discovered that OpenSSL incorrectly

handled certain crafted CBC data when used with AES-NI. A remote attacker

could use this issue to cause OpenSSL to crash, resulting in a denial of

service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 12.10.

(CVE-2012-2686)

Stephen Henson discovered that OpenSSL incorrectly performed signature

verification for OCSP responses. A remote attacker could use this issue to

cause OpenSSL to crash, resulting in a denial of service. (CVE-2013-0166)

Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used

in OpenSSL was vulnerable to a timing side-channel attack known as the

"Lucky Thirteen" issue. A remote attacker could use this issue to perform

plaintext-recovery attacks via analysis of timing data. (CVE-2013-0169)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  libssl1.0.0                     1.0.1c-3ubuntu2.1

Ubuntu 12.04 LTS:
  libssl1.0.0                     1.0.1-4ubuntu5.6

Ubuntu 11.10:
  libssl1.0.0                     1.0.0e-2ubuntu4.7

Ubuntu 10.04 LTS:
  libssl0.9.8                     0.9.8k-7ubuntu8.14

Ubuntu 8.04 LTS:
  libssl0.9.8                     0.9.8g-4ubuntu3.20

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1732-1

CVE-2012-2686, CVE-2013-0166, CVE-2013-0169

Severity
critical
Lowest
Low
Medium
High
Critical

February 21, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.