Опубликовано: 01 мар. 2016
Источник: oracle-oval
Платформа: Oracle Linux 6
Платформа: Oracle Linux 7
Описание
ELSA-2016-3523: openssl security update (IMPORTANT)
[1.0.1e-51.4]
- fix CVE-2016-0702 - side channel attack on modular exponentiation
- fix CVE-2016-0705 - double-free in DSA private key parsing
- fix CVE-2016-0797 - heap corruption in BN_hex2bn and BN_dec2bn
[1.0.1e-51.3]
- fix CVE-2015-3197 - SSLv2 ciphersuite enforcement
- disable SSLv2 in the generic TLS method
[1.0.1e-51.2]
- fix CVE-2015-7575 - disallow use of MD5 in TLS1.2
[1.0.1e-51.1]
- fix CVE-2015-3194 - certificate verify crash with missing PSS parameter
- fix CVE-2015-3195 - X509_ATTRIBUTE memory leak
- fix CVE-2015-3196 - race condition when handling PSK identity hint
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
openssl
1.0.1e-42.ksplice1.el6_7.4
openssl-devel
1.0.1e-42.ksplice1.el6_7.4
openssl-perl
1.0.1e-42.ksplice1.el6_7.4
openssl-static
1.0.1e-42.ksplice1.el6_7.4
Oracle Linux 7
Oracle Linux x86_64
openssl
1.0.1e-51.ksplice1.el7_2.4
openssl-devel
1.0.1e-51.ksplice1.el7_2.4
openssl-libs
1.0.1e-51.ksplice1.el7_2.4
openssl-perl
1.0.1e-51.ksplice1.el7_2.4
openssl-static
1.0.1e-51.ksplice1.el7_2.4