Oval Definition:oval:com.redhat.rhsa:def:20060661
Revision Date:2006-09-06Version:641
Title:RHSA-2006:0661: openssl security update (Important)
Description:The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols.

Daniel Bleichenbacher recently described an attack on PKCS #1 v1.5 signatures. Where an RSA key with exponent 3 is used it may be possible for an attacker to forge a PKCS #1 v1.5 signature that would be incorrectly verified by implementations that do not check for excess data in the RSA exponentiation result of the signature.

  • The Google Security Team discovered that OpenSSL is vulnerable to this attack. This issue affects applications that use OpenSSL to verify X.509 certificates as well as other uses of PKCS #1 v1.5. (CVE-2006-4339)

    This errata also resolves a problem where a customized ca-bundle.crt file was overwritten when the openssl package was upgraded.

    Users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue.

    Note: After installing this update, users are advised to either restart all services that use OpenSSL or restart their system.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-4339
    RHSA-2006:0661
    RHSA-2006:0661-01
    RHSA-2006:0661-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • openssl096b is earlier than 0:0.9.6b-16.43
  • AND openssl096b is signed with Red Hat master key
  • openssl-perl is earlier than 0:0.9.7a-33.18
  • AND openssl-perl is signed with Red Hat master key
  • openssl is earlier than 0:0.9.7a-33.18
  • AND openssl is signed with Red Hat master key
  • openssl-devel is earlier than 0:0.9.7a-33.18
  • AND openssl-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssl096b is earlier than 0:0.9.6b-22.43
  • AND openssl096b is signed with Red Hat master key
  • openssl is earlier than 0:0.9.7a-43.11
  • AND openssl is signed with Red Hat master key
  • openssl-devel is earlier than 0:0.9.7a-43.11
  • AND openssl-devel is signed with Red Hat master key
  • openssl-perl is earlier than 0:0.9.7a-43.11
  • AND openssl-perl is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssl096b is earlier than 0:0.9.6b-22.43
  • AND openssl096b is signed with Red Hat redhatrelease2 key
  • openssl is earlier than 0:0.9.7a-43.11
  • AND openssl is signed with Red Hat redhatrelease2 key
  • openssl-devel is earlier than 0:0.9.7a-43.11
  • AND openssl-devel is signed with Red Hat redhatrelease2 key
  • openssl-perl is earlier than 0:0.9.7a-43.11
  • AND openssl-perl is signed with Red Hat redhatrelease2 key
  • BACK