Date: 20 April 2012
References: ESB-2012.0027 ESB-2012.0062 ESB-2012.0269 ESB-2012.0388 ESB-2012.0408 ESB-2012.0866 ESB-2013.0309 ESB-2013.0537
Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2012.0389
openssl security update
20 April 2012
===========================================================================
AusCERT Security Bulletin Summary
---------------------------------
Product: openssl
Publisher: Debian
Operating System: Debian GNU/Linux 6
Impact/Access: Access Confidential Data -- Remote/Unauthenticated
Denial of Service -- Remote/Unauthenticated
Resolution: Patch/Upgrade
CVE Names: CVE-2012-2110 CVE-2012-1165 CVE-2012-0884
CVE-2011-4619
Reference: ESB-2012.0388
ESB-2012.0269
ESB-2012.0062
ESB-2012.0027
Original Bulletin:
http://www.debian.org/security/2012/dsa-2454
- --------------------------BEGIN INCLUDED TEXT--------------------
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - -------------------------------------------------------------------------
Debian Security Advisory DSA-2454-1 security@debian.org
http://www.debian.org/security/ Raphael Geissert
April 19, 2012 http://www.debian.org/security/faq
- - -------------------------------------------------------------------------
Package : openssl
Vulnerability : multiple
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-0884 CVE-2012-1165 CVE-2012-2110
Multiple vulnerabilities have been found in OpenSSL. The Common
Vulnerabilities and Exposures project identifies the following issues:
CVE-2012-0884
Ivan Nestlerode discovered a weakness in the CMS and PKCS #7
implementations that could allow an attacker to decrypt data
via a Million Message Attack (MMA).
CVE-2012-1165
It was discovered that a NULL pointer could be dereferenced
when parsing certain S/MIME messages, leading to denial of
service.
CVE-2012-2110
Tavis Ormandy, Google Security Team, discovered a vulnerability
in the way DER-encoded ASN.1 data is parsed that can result in
a heap overflow.
Additionally, the fix for CVE-2011-4619 has been updated to address an
issue with SGC handshakes.
For the stable distribution (squeeze), these problems have been fixed in
version 0.9.8o-4squeeze11.
For the testing distribution (wheezy), these problems will be fixed soon.
For the unstable distribution (sid), these problems have been fixed in
version 1.0.1a-1.
We recommend that you upgrade your openssl packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iEYEARECAAYFAk+QgdEACgkQYy49rUbZzlrPxACgmA4me/ZAVZS/TDIifkHgiU9q
x/QAn0pU8BwEFv8ugmm746OX7jDQMnYP
=JCSE
- -----END PGP SIGNATURE-----
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
http://www.auscert.org.au/render.html?cid=1980
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967
iQIVAwUBT5C0Ie4yVqjM2NGpAQLvrBAAngxM4Fz/vzEM2BSfB1CCfZAhiao5Riok
wcvpgpI9eAa0njVZ071AJiXSzLhBcqiOvKM6VF2RL0R0zTLIm01iQGEcMQxz2v9Z
eartSP+wy2HEW+l/V42g4FG1FhYqXCn15I5hcbqRn8+yVcATilZdL6FeR8geOzBM
A5istSAG4rxBZz8JP9L99VbSk33AWXr5SRv1MXtptsVnY69h08reG8nGfIEpQ0fR
V0xVFLUEFjlIANK1teXQqLJoW6e0WiKjEkOroGF9AWYqMb1HVkh11g9C2DS8V/EG
OH4Qjb5RPdLtUaL1OA8bNHtP8WPDPrPPnXjv3nnLv8B4SLay7nGrSCCGH20rsvf/
jdtA0kDv1/fQWOCq/D3FXIkFuquB7e5IffKgDT9O9nFbR43bpI9zbvLhv966c8kF
qKZ3FNc20pzhsJ9lg2d20lbV1eYTV3aVd1l+/X4X1JeN6wCUoq7dwQNwFfeWKpWz
y9xYwjHmSzQ67huW/F/eDcUkV7+rDCfLdW1qsBxhVePs8KX83HIXDCgl91XCJCkw
L/FvXYS81U1rPQwYAfDGFshlJuB1e44hMwS6GwUjgm/UUq+bv445lfsC9vuKR7pg
b9BxcQaXexdj+BRBu/4EDdtYj8lZeWhfNH8LokPXIdohkbywKQK9urHTJA9KLIOe
Py6vSekg26E=
=Ljyz
-----END PGP SIGNATURE-----
|