Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 15.10: USN-2883-1 Important Security Update for OpenSSL Network Leak

Ubuntu Large Esm H500
OpenSSL could be made to expose sensitive information over the network.
=========================================================================Ubuntu Security Notice USN-2883-1
January 28, 2016

openssl vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

OpenSSL could be made to expose sensitive information over the network.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Antonio Sanso discovered that OpenSSL reused the same private DH exponent
for the life of a server process when configured with a X9.42 style
parameter file. This could allow a remote attacker to possibly discover the
server's private DH exponent when being used with non-safe primes.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libssl1.0.0                     1.0.2d-0ubuntu1.3

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2883-1
  CVE-2016-0701

Package Information:
  https://launchpad.net/ubuntu/+source/openssl/1.0.2d-0ubuntu1.3


Ubuntu 15.10: USN-2883-1 Important Security Update for OpenSSL Network Leak

ubuntu
Calendar Grey January 28, 2016
Dist Ubuntu Esm H88
A flaw in OpenSSL reveals confidential information across networks; ensure your Ubuntu installation is current to improve protections.
OpenSSL could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libssl1.0.0 1.0.2d-0ubuntu1.3 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2883-1

CVE-2016-0701

Severity
important
Lowest
Low
Medium
High
Critical

January 28, 2016

Package Information

https://launchpad.net/ubuntu/+source/openssl/1.0.2d-0ubuntu1.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here