Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 15.10: 2914-1 Moderate: OpenSSL Denial Of Service Threats

ubuntu
Calendar Grey March 1, 2016
Scroller Ubuntu
Multiple vulnerabilities affecting OpenSSL have been resolved in Ubuntu. Urgent updates are essential for maintaining system security and safeguarding data.
Several security issues were fixed in OpenSSL.

Summary

Several security issues were fixed in OpenSSL.

Software Description:

- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Yuval Yarom, Daniel Genkin, and Nadia Heninger discovered that OpenSSL was

vulnerable to a side-channel attack on modular exponentiation. On certain

CPUs, a local attacker could possibly use this issue to recover RSA keys.

This flaw is known as CacheBleed. (CVE-2016-0702)

Adam Langley discovered that OpenSSL incorrectly handled memory when

parsing DSA private keys. A remote attacker could use this issue to cause

OpenSSL to crash, resulting in a denial of service, or possibly execute

arbitrary code. (CVE-2016-0705)

Guido Vranken discovered that OpenSSL incorrectly handled hex digit

calculation in the BN_hex2bn function. A remote attacker could use this

issue to cause OpenSSL to crash, resulting in a denial of service, or

possibly execute arbitrary code. (CVE-2016-0797)

Emilia Käsper discovered that OpenSSL in...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libssl1.0.0                     1.0.2d-0ubuntu1.4

Ubuntu 14.04 LTS:
  libssl1.0.0                     1.0.1f-1ubuntu2.18

Ubuntu 12.04 LTS:
  libssl1.0.0                     1.0.1-4ubuntu5.35

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2914-1

CVE-2016-0702, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798,

CVE-2016-0799

Severity
important
Lowest
Low
Medium
High
Critical

March 01, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.