Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux ASA-201512-2 High Severity: OpenSSL Multiple Risks

The packages openssl and lib32-openssl before version 1.0.2.e-1 are vulnerable to multiple issues including memory leaks, denial of service, double free. If you use DHE there is a possibility that organizations with enough system resources can guess your private key. . Arch Linux Security Advisory ASA-201512-2 ======================================== Severity: High Date : 2015-12-05 CVE-ID : CVE-2015-3193 CVE-2015-3194 CVE-2015-3195 CVE-2015-3196 CVE-2015-1794 Package : openssl lib32-openssl Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The packages openssl and lib32-openssl before version 1.0.2.e-1 are vulnerable to multiple issues including memory leaks, denial of service, double free. If you use DHE there is a possibility that organizations with enough system resources can guess your private key. Resolution ========= Upgrade to 1.0.2.e-1. # pacman -Syu "openssl> =1.0.2.e-1" If you use lib32-openssl it is strongly recommended to upgrade this package as well. # pacman -Syu "lib32-openssl> =1.0.2.e-1" The problems have been fixed upstream in version 1.0.2.e. Workaround ========= None. Description ========== - CVE-2015-3193 (insecure private key in connection with DHE) There is a carry propagating bug in the x86_64 Montgomery squaring procedure. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. For examplethis can occur by default in OpenSSL DHE based SSL/TLS ciphersuites.[1] - CVE-2015-3194 (denial of service) The signature verification routines will crash with a NULL pointer dereference if presented with an ASN.1 signature using the RSA PSS algorithm and absent mask generation function parameter. Since these routines are used to verify certificate signature algorithms this can be used to crash any certificate verification operation and exploited in a DoS attack. Any application which performs certificate verification is vulnerable including OpenSSL clients and servers which enable client authentication.[2] - CVE-2015-3195 (memory leaks) When presented with a malformed X509_ATTRIBUTE structure OpenSSL will leak memory. This structure is used by the PKCS#7 and CMS routines so any application which reads PKCS#7 or CMS data from untrusted sources is affected. SSL/TLS is not affected.[3] - CVE-2015-3196 (double free) If PSK identity hints are received by a multi-threaded client then the values are wrongly updated in the parent SSL_CTX structure. This can result in a race condition potentially leading to a double free of the identify hint data.[4] - CVE-2015-1794 (denial of service) If a client receives a ServerKeyExchange for an anonymous DH ciphersuite with the value of p set to 0 then a seg fault can occur leading to a possible denial of service attack.[5] Impact ===== A remote attacker is possible to guess the private key (only when DHE is used) with enough resources (e.g NSA/GHCQ), crash openssl (denial of service) and make use of memory leaks.[6] References ========= [1] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3193 [2] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3194 [3] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3195 [4] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3196 [5] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1794 [6] https://openssl-library.org/news/secadv/20151203.txt . Arch Linux Security Notification ASA-202310-1:Critical vulnerabilities discovered in openssl and lib32-openssl, necessitating immediate updates.. OpenSSL Issues, Arch Linux Advisory, Lib32 Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 05, 2015 Important ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here