Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 13.04 USN-1898-1 Critical: OpenSSL Information Exposure

ubuntu
Calendar Grey July 4, 2013
Scroller Ubuntu
Implement the patch for the OpenSSL security flaw in Ubuntu to safeguard against potential data leaks during transmission. Discover additional details here.
Applications could be made to expose sensitive information over thenetwork.

Summary

Applications could be made to expose sensitive information over the

network.

Software Description:

- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

The TLS protocol 1.2 and earlier can encrypt compressed data without

properly obfuscating the length of the unencrypted data, which allows

man-in-the-middle attackers to obtain plaintext content by observing

length differences during a series of guesses in which a provided string

potentially matches an unknown string in encrypted and compressed traffic.

This is known as a CRIME attack in HTTP. Other protocols layered on top of

TLS may also make these attacks practical.

This update disables compression for all programs using SSL and TLS

provided by the OpenSSL library. To re-enable compression for programs

that need compression to communicate with legacy services, define the

variable OPENSSL_DEFAULT_ZLIB in the program's environment.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  libssl1.0.0                     1.0.1c-4ubuntu8.1

Ubuntu 12.10:
  libssl1.0.0                     1.0.1c-3ubuntu2.5

Ubuntu 12.04 LTS:
  libssl1.0.0                     1.0.1-4ubuntu5.10

Ubuntu 10.04 LTS:
  libssl0.9.8                     0.9.8k-7ubuntu8.15

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1898-1

CVE-2012-4929

Severity
critical
Lowest
Low
Medium
High
Critical

July 04, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.