You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa OpenSSL

Sigurnosni nedostaci programskog paketa OpenSSL

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Gentoo Linux Security Advisory GLSA 201407-05
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
http://security.gentoo.org/
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Severity: High
Title: OpenSSL: Multiple vulnerabilities
Date: July 27, 2014
Bugs: #512506
ID: 201407-05

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Synopsis
========

Multiple vulnerabilities have been found in OpenSSL, possibly allowing
remote attackers to execute arbitrary code.

Background
==========

OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
(SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general
purpose cryptography library.

Affected packages
=================

——————————————————————-
Package / Vulnerable / Unaffected
——————————————————————-
1 dev-libs/openssl < 1.0.1h-r1 *>= 0.9.8z_p5
*>= 0.9.8z_p4
*>= 0.9.8z_p1
*>= 0.9.8z_p3
*>= 0.9.8z_p2
*>= 1.0.0m
>= 1.0.1h-r1

Description
===========

Multiple vulnerabilities have been discovered in OpenSSL. Please review
the OpenSSL Security Advisory [05 Jun 2014] and the CVE identifiers
referenced below for details.

Impact
======

A remote attacker could send specially crafted DTLS fragments to an
OpenSSL DTLS client or server to possibly execute arbitrary code with
the privileges of the process using OpenSSL.

Furthermore, an attacker could force the use of weak keying material in
OpenSSL SSL/TLS clients and servers, inject data across sessions, or
cause a Denial of Service via various vectors.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All OpenSSL users should upgrade to the latest version:

# emerge –sync
# emerge –ask –oneshot –verbose “>=dev-libs/openssl-1.0.1h-r1”

References
==========

[ 1 ] CVE-2010-5298
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-5298
[ 2 ] CVE-2014-0195
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0195
[ 3 ] CVE-2014-0198
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0198
[ 4 ] CVE-2014-0221
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0221
[ 5 ] CVE-2014-0224
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0224
[ 6 ] CVE-2014-3470
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3470
[ 7 ] OpenSSL Security Advisory [05 Jun 2014]
http://www.openssl.org/news/secadv_20140605.txt

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201407-05.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users’ machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2014 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons – Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2.0.22 (GNU/Linux)

iQIcBAEBCAAGBQJT1YCfAAoJEByNLmvcM7DuL5kP/AhJUY/Bzokgj6+Tra1sZqJz
y38nZvzAfI1hc74MVmfBxtw+DTCKXwzEag0hbLDc/MD5KJFkvLP+uq/DdD9yN472
NlNSNsbt+sPV3Rc0+BI4SKpN6Q8HwUAr2PHU2ZtFWGuGbrv9GwtxoH949z5slIdJ
Kqu1bo5yEYVOIXDYg7ADgd0O+EKwdzjXusGWV6spn2XWfZg9GaKCDRG0f0XGT6a9
4BrNhB+5/VEZDaYpoMjcijBbjU4+OTWDFJtFfDEye6y6CpSG6eIbcm+BVPnKoLj3
UbxMqc5jnGB67X7Sd9hlgO6rxinVVbQ1h6tI6OsNiswMRoUdguBM5eYF93UZWl4j
0F6lnd+U88s9oCyHT7bDYXbux47U/OINASB13jl7zSONbFQ5xRCm3Nsypy3abfrn
QK4hv3B3Cbw/G0/EWGU9PcOnbe871JyUk9cIxxBhpw0rI/Wgi+ZrXtVqawmw9SkI
j+5RjO9eSlzI+tv2V3tw6GFbypceK6mFTzOz3NvGYknKB8znQeaB0dcfJLh4xgWV
Q+Xr7mYLt7q0FWwA7mDfh+n607UA8gAYgA+esRE4/2UK6riA8aOego31fQehQKK1
IfBpFsTIC9n9sBPosOUPMTs6UhtKsopIAS+3DsFb0zbX0Lg/vsdG3Dxkt1aO7Z2Z
Of0HsMzQLYNjaW03XVza
=D7hH
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa cobbler

Otkriven je sigurnosni nedostatak u programskom paketu cobbler. Otkriveni nedostatak se javlja u web sučelju i potencijalnim napadačima omogućuje čitanje...

Close