Oval Definition:oval:com.ubuntu.precise:def:20140160000
Revision Date:2014-04-07Version:1
Title:CVE-2014-0160 on Ubuntu 12.04 LTS (precise) - high.
Description:The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-0160
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • The 'openssl' package in precise was vulnerable but has been fixed (note: '1.0.1-4ubuntu5.12').
  • OR NOT While related to the CVE in some way, the 'openssl098' package in precise is not affected.
  • BACK