Oval Definition:
oval:org.mitre.oval:def:7738
Revision Date
:
2014-06-23
Version
:
18
Title
:
DSA-1701 openssl, openssl097 -- interpretation conflict
Description
:
It was discovered that OpenSSL does not properly verify DSA signatures on X.509 certificates due to an API misuse, potentially leading to the acceptance of incorrect X.509 certificates as genuine (CVE-2008-5077).
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2008-5077
DSA-1701
Platform(s)
:
Debian GNU/Linux 4.0
Product(s)
:
openssl
openssl097
Definition Synopsis
Debian GNU/Linux 4.0 is installed.
AND
Architecture section
Architecture dependent section
Supported architectures section
Installed architecture is s390
OR
Installed architecture is amd64
OR
Installed architecture is sparc
OR
Installed architecture is powerpc
OR
Installed architecture is i386
OR
Installed architecture is ia64
OR
Installed architecture is alpha
OR
Installed architecture is mipsel
OR
Installed architecture is hppa
AND
Packages section
libssl0.9.7-dbg is earlier than 0.9.7k-3.1etch2
OR
libssl-dev is earlier than 0.9.8c-4etch4
OR
libssl0.9.8-dbg is earlier than 0.9.8c-4etch4
OR
openssl is earlier than 0.9.8c-4etch4
OR
libssl0.9.8 is earlier than 0.9.8c-4etch4
OR
libssl0.9.7 is earlier than 0.9.7k-3.1etch2
OR
Architecture dependent section
Installed architecture is mips
AND
Packages section
libssl-dev is earlier than 0.9.8c-4etch4
OR
libssl0.9.8-dbg is earlier than 0.9.8c-4etch4
OR
libssl0.9.8 is earlier than 0.9.8c-4etch4
OR
openssl is earlier than 0.9.8c-4etch4
BACK