Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-1840

Опубликовано: 05 мая 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-1840: openssl security and bug fix update (MODERATE)

[1.1.1c-15]

  • add selftest of the RAND_DRBG implementation

[1.1.1c-14]

  • fix incorrect error return value from FIPS_selftest_dsa
  • S390x: properly restore SIGILL signal handler

[1.1.1c-12]

  • additional fix for the edk2 build

[1.1.1c-9]

  • disallow use of SHA-1 signatures in TLS in FIPS mode

[1.1.1c-8]

  • fix CVE-2019-1547 - side-channel weak encryption vulnerability
  • fix CVE-2019-1563 - padding oracle in CMS API
  • fix CVE-2019-1549 - ensure fork safety of the DRBG
  • fix handling of non-FIPS allowed EC curves in FIPS mode
  • fix TLS compliance issues

[1.1.1c-7]

  • backported ARM performance fixes from master

[1.1.1c-6]

  • backport of S390x ECC CPACF enhancements from master
  • FIPS mode: properly disable 1024 bit DSA key generation
  • FIPS mode: skip ED25519 and ED448 algorithms in openssl speed
  • FIPS mode: allow AES-CCM ciphersuites

[1.1.1c-5]

  • make the code suitable for edk2 build

[1.1.1c-4]

  • backport of SSKDF from master

[1.1.1c-3]

  • backport of KBKDF and KRB5KDF from master

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

openssl

1.1.1c-15.el8

openssl-devel

1.1.1c-15.el8

openssl-libs

1.1.1c-15.el8

openssl-perl

1.1.1c-15.el8

Oracle Linux x86_64

openssl

1.1.1c-15.el8

openssl-devel

1.1.1c-15.el8

openssl-libs

1.1.1c-15.el8

openssl-perl

1.1.1c-15.el8

Связанные уязвимости

suse-cvrf
около 6 лет назад

Security update for openssl-1_1

suse-cvrf
больше 6 лет назад

Security update for openssl-1_0_0

suse-cvrf
больше 6 лет назад

Security update for openssl-1_0_0

suse-cvrf
больше 6 лет назад

Security update for openssl-1_1

suse-cvrf
больше 6 лет назад

Security update for openssl-1_1