Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-0996

Опубликовано: 12 мая 2016
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2016-0996: openssl security update (IMPORTANT)

[1.0.1e-48.1]

  • fix CVE-2016-2105 - possible overflow in base64 encoding
  • fix CVE-2016-2106 - possible overflow in EVP_EncryptUpdate()
  • fix CVE-2016-2107 - padding oracle in stitched AES-NI CBC-MAC
  • fix CVE-2016-2108 - memory corruption in ASN.1 encoder
  • fix CVE-2016-2109 - possible DoS when reading ASN.1 data from BIO
  • fix CVE-2016-0799 - memory issues in BIO_printf

[1.0.1e-48]

  • fix CVE-2016-0702 - side channel attack on modular exponentiation
  • fix CVE-2016-0705 - double-free in DSA private key parsing
  • fix CVE-2016-0797 - heap corruption in BN_hex2bn and BN_dec2bn

[1.0.1e-47]

  • fix CVE-2015-3197 - SSLv2 ciphersuite enforcement
  • disable SSLv2 in the generic TLS method

[1.0.1e-46]

  • fix 1-byte memory leak in pkcs12 parse (#1229871)
  • document some options of the speed command (#1197095)

[1.0.1e-45]

  • fix high-precision timestamps in timestamping authority

[1.0.1e-44]

  • fix CVE-2015-7575 - disallow use of MD5 in TLS1.2

[1.0.1e-43]

  • fix CVE-2015-3194 - certificate verify crash with missing PSS parameter
  • fix CVE-2015-3195 - X509_ATTRIBUTE memory leak
  • fix CVE-2015-3196 - race condition when handling PSK identity hint

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

openssl

1.0.1e-48.el6_8.1

openssl-devel

1.0.1e-48.el6_8.1

openssl-perl

1.0.1e-48.el6_8.1

openssl-static

1.0.1e-48.el6_8.1

Oracle Linux i686

openssl

1.0.1e-48.el6_8.1

openssl-devel

1.0.1e-48.el6_8.1

openssl-perl

1.0.1e-48.el6_8.1

openssl-static

1.0.1e-48.el6_8.1

Связанные уязвимости

oracle-oval
около 9 лет назад

ELSA-2016-3571: openssl-fips security update (IMPORTANT)

oracle-oval
около 9 лет назад

ELSA-2016-3558: openssl security update (IMPORTANT)

oracle-oval
около 9 лет назад

ELSA-2016-3556: openssl security update (IMPORTANT)

oracle-oval
около 9 лет назад

ELSA-2016-0722: openssl security update (IMPORTANT)

suse-cvrf
около 9 лет назад

Security update for openssl