Oval Definition:oval:com.redhat.rhsa:def:20050476
Revision Date:2005-06-01Version:502
Title:RHSA-2005:476: openssl security update (Moderate)
Description:OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library.

Colin Percival reported a cache timing attack that could allow a malicious local user to gain portions of cryptographic keys. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CAN-2005-0109 to the issue. The OpenSSL library has been patched to add a new fixed-window mod_exp implementation as default for RSA, DSA, and DH private-key operations. This patch is designed to mitigate cache timing and potentially related attacks.

A flaw was found in the way the der_chop script creates temporary files. It is possible that a malicious local user could cause der_chop to overwrite files (CAN-2004-0975). The der_chop script was deprecated and has been removed from these updated packages. Red Hat Enterprise Linux 4 did not ship der_chop and is therefore not vulnerable to this issue.

Users are advised to update to these erratum packages which contain patches to correct these issues.

Please note: After installing this update, users are advised to either restart all services that use OpenSSL or restart their system.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0975
CVE-2005-0109
RHSA-2005:476-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • openssl096b is earlier than 0:0.9.6b-16.22.3
  • AND openssl096b is signed with Red Hat master key
  • openssl is earlier than 0:0.9.7a-33.15
  • AND openssl is signed with Red Hat master key
  • openssl-perl is earlier than 0:0.9.7a-33.15
  • AND openssl-perl is signed with Red Hat master key
  • openssl-devel is earlier than 0:0.9.7a-33.15
  • AND openssl-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssl096b is earlier than 0:0.9.6b-22.3
  • AND openssl096b is signed with Red Hat master key
  • openssl is earlier than 0:0.9.7a-43.2
  • AND openssl is signed with Red Hat master key
  • openssl-perl is earlier than 0:0.9.7a-43.2
  • AND openssl-perl is signed with Red Hat master key
  • openssl-devel is earlier than 0:0.9.7a-43.2
  • AND openssl-devel is signed with Red Hat master key
  • BACK