Oval Definition:oval:com.redhat.rhsa:def:20161137
Revision Date:2016-05-31Version:635
Title:RHSA-2016:1137: openssl security update (Important)
Description:OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

  • A flaw was found in the way OpenSSL encoded certain ASN.1 data structures. An attacker could use this flaw to create a specially crafted certificate which, when verified or re-encoded by OpenSSL, could cause it to crash, or execute arbitrary code using the permissions of the user running an application compiled against the OpenSSL library. (CVE-2016-2108)

    Red Hat would like to thank the OpenSSL project for reporting this issue. Upstream acknowledges Huzaifa Sidhpurwala (Red Hat), Hanno Böck, and David Benjamin (Google) as the original reporters.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-2108
    RHSA-2016:1137
    RHSA-2016:1137-00
    RHSA-2016:1137-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • openssl is earlier than 0:0.9.8e-40.el5_11
  • AND openssl is signed with Red Hat redhatrelease2 key
  • openssl-devel is earlier than 0:0.9.8e-40.el5_11
  • AND openssl-devel is signed with Red Hat redhatrelease2 key
  • openssl-perl is earlier than 0:0.9.8e-40.el5_11
  • AND openssl-perl is signed with Red Hat redhatrelease2 key
  • BACK