Oval Definition:oval:com.redhat.rhsa:def:20150066
Revision Date:2015-01-21Version:637
Title:RHSA-2015:0066: openssl security update (Moderate)
Description:OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Datagram Transport Layer Security (DTLS) protocols, as well as a full-strength, general purpose cryptography library.

  • A NULL pointer dereference flaw was found in the DTLS implementation of OpenSSL. A remote attacker could send a specially crafted DTLS message, which would cause an OpenSSL server to crash. (CVE-2014-3571)

  • A memory leak flaw was found in the way the dtls1_buffer_record() function of OpenSSL parsed certain DTLS messages. A remote attacker could send multiple specially crafted DTLS messages to exhaust all available memory of a DTLS server. (CVE-2015-0206)

  • It was found that OpenSSL's BigNumber Squaring implementation could produce incorrect results under certain special conditions. This flaw could possibly affect certain OpenSSL library functionality, such as RSA blinding. Note that this issue occurred rarely and with a low probability, and there is currently no known way of exploiting it. (CVE-2014-3570)

  • It was discovered that OpenSSL would perform an ECDH key exchange with a non-ephemeral key even when the ephemeral ECDH cipher suite was selected. A malicious server could make a TLS/SSL client using OpenSSL use a weaker key exchange method than the one requested by the user. (CVE-2014-3572)

  • It was discovered that OpenSSL would accept ephemeral RSA keys when using non-export RSA cipher suites. A malicious server could make a TLS/SSL client using OpenSSL use a weaker key exchange method. (CVE-2015-0204)

  • Multiple flaws were found in the way OpenSSL parsed X.509 certificates. An attacker could use these flaws to modify an X.509 certificate to produce a certificate with a different fingerprint without invalidating its signature, and possibly bypass fingerprint-based blacklisting in applications. (CVE-2014-8275)

  • It was found that an OpenSSL server would, under certain conditions, accept Diffie-Hellman client certificates without the use of a private key. An attacker could use a user's client certificate to authenticate as that user, without needing the private key. (CVE-2015-0205)

    All OpenSSL users are advised to upgrade to these updated packages, which contain a backported patch to mitigate the above issues. For the update to take effect, all services linked to the OpenSSL library (such as httpd and other SSL-enabled services) must be restarted or the system rebooted.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-3570
    CVE-2014-3571
    CVE-2014-3572
    CVE-2014-8275
    CVE-2015-0204
    CVE-2015-0205
    CVE-2015-0206
    RHSA-2015:0066
    RHSA-2015:0066-00
    RHSA-2015:0066-02
    Platform(s):Red Hat Enterprise Linux 6
    Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • openssl is earlier than 1:1.0.1e-34.el7_0.7
  • AND openssl is signed with Red Hat redhatrelease2 key
  • openssl-devel is earlier than 1:1.0.1e-34.el7_0.7
  • AND openssl-devel is signed with Red Hat redhatrelease2 key
  • openssl-libs is earlier than 1:1.0.1e-34.el7_0.7
  • AND openssl-libs is signed with Red Hat redhatrelease2 key
  • openssl-perl is earlier than 1:1.0.1e-34.el7_0.7
  • AND openssl-perl is signed with Red Hat redhatrelease2 key
  • openssl-static is earlier than 1:1.0.1e-34.el7_0.7
  • AND openssl-static is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • openssl is earlier than 0:1.0.1e-30.el6_6.5
  • AND openssl is signed with Red Hat redhatrelease2 key
  • openssl-devel is earlier than 0:1.0.1e-30.el6_6.5
  • AND openssl-devel is signed with Red Hat redhatrelease2 key
  • openssl-perl is earlier than 0:1.0.1e-30.el6_6.5
  • AND openssl-perl is signed with Red Hat redhatrelease2 key
  • openssl-static is earlier than 0:1.0.1e-30.el6_6.5
  • AND openssl-static is signed with Red Hat redhatrelease2 key
  • BACK