Oval Definition:oval:org.mitre.oval:def:28712
Revision Date:2015-08-17Version:10
Title:RHSA-2009:0004 -- openssl security update (Important)
Description:Updated OpenSSL packages that correct a security issue are now availablefor Red Hat Enterprise Linux 2.1, 3, 4, and 5.This update has been rated as having important security impact by the RedHat Security Response Team.OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) andTransport Layer Security (TLS v1) protocols as well as a full-strength,general purpose, cryptography library.The Google security team discovered a flaw in the way OpenSSL checked theverification of certificates. An attacker in control of a malicious server,or able to effect a man in the middle attack, could present a malformedSSL/TLS signature from a certificate chain to a vulnerable client andbypass validation. (CVE-2008-5077)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2009:0004-CentOS 2
CESA-2009:0004-CentOS 3
CESA-2009:0004-CentOS 5
CVE-2008-5077
RHSA-2009:0004
Platform(s):CentOS Linux 2
CentOS Linux 3
CentOS Linux 5
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Product(s):openssl
openssl095a
openssl096
openssl096b
openssl097a
Definition Synopsis
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • openssl-devel is earlier than 0:0.9.8b-10.el5_2.1
  • OR openssl is earlier than 0:0.9.8b-10.el5_2.1
  • OR openssl-perl is earlier than 0:0.9.8b-10.el5_2.1
  • OR openssl097a is earlier than 0:0.9.7a-9.el5_2.1
  • Red Hat Enterprise Linux 3 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 3
  • AND Packages match section
  • openssl is earlier than 0:0.9.7a-33.25
  • OR openssl-devel is earlier than 0:0.9.7a-33.25
  • OR openssl-perl is earlier than 0:0.9.7a-33.25
  • OR openssl096b is earlier than 0:0.9.6b-16.49
  • Red Hat Enterprise Linux 4 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 4
  • AND Packages match section
  • openssl is earlier than 0:0.9.7a-43.17.el4_7.2
  • OR openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2
  • OR openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2
  • OR openssl096b is earlier than 0:0.9.6b-22.46.el4_7
  • BACK