copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2012.0389 - [Debian] openssl: Multiple vulnerabilities

Date: 20 April 2012
References: ESB-2012.0027  ESB-2012.0062  ESB-2012.0269  ESB-2012.0388  ESB-2012.0408  ESB-2012.0866  ESB-2013.0309  ESB-2013.0537  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2012.0389
                          openssl security update
                               20 April 2012

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           openssl
Publisher:         Debian
Operating System:  Debian GNU/Linux 6
Impact/Access:     Access Confidential Data -- Remote/Unauthenticated
                   Denial of Service        -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2012-2110 CVE-2012-1165 CVE-2012-0884
                   CVE-2011-4619  

Reference:         ESB-2012.0388
                   ESB-2012.0269
                   ESB-2012.0062
                   ESB-2012.0027

Original Bulletin: 
   http://www.debian.org/security/2012/dsa-2454

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-2454-1                   security@debian.org
http://www.debian.org/security/                          Raphael Geissert
April 19, 2012                         http://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : openssl
Vulnerability  : multiple
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2012-0884 CVE-2012-1165 CVE-2012-2110

Multiple vulnerabilities have been found in OpenSSL. The Common
Vulnerabilities and Exposures project identifies the following issues:

CVE-2012-0884

	Ivan Nestlerode discovered a weakness in the CMS and PKCS #7
	implementations that could allow an attacker to decrypt data
	via a Million Message Attack (MMA).

CVE-2012-1165

	It was discovered that a NULL pointer could be dereferenced
	when parsing certain S/MIME messages, leading to denial of
	service.

CVE-2012-2110

	Tavis Ormandy, Google Security Team, discovered a vulnerability
	in the way DER-encoded ASN.1 data is parsed that can result in
	a heap overflow.


Additionally, the fix for CVE-2011-4619 has been updated to address an
issue with SGC handshakes.

For the stable distribution (squeeze), these problems have been fixed in
version 0.9.8o-4squeeze11.

For the testing distribution (wheezy), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in
version 1.0.1a-1.

We recommend that you upgrade your openssl packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk+QgdEACgkQYy49rUbZzlrPxACgmA4me/ZAVZS/TDIifkHgiU9q
x/QAn0pU8BwEFv8ugmm746OX7jDQMnYP
=JCSE
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBT5C0Ie4yVqjM2NGpAQLvrBAAngxM4Fz/vzEM2BSfB1CCfZAhiao5Riok
wcvpgpI9eAa0njVZ071AJiXSzLhBcqiOvKM6VF2RL0R0zTLIm01iQGEcMQxz2v9Z
eartSP+wy2HEW+l/V42g4FG1FhYqXCn15I5hcbqRn8+yVcATilZdL6FeR8geOzBM
A5istSAG4rxBZz8JP9L99VbSk33AWXr5SRv1MXtptsVnY69h08reG8nGfIEpQ0fR
V0xVFLUEFjlIANK1teXQqLJoW6e0WiKjEkOroGF9AWYqMb1HVkh11g9C2DS8V/EG
OH4Qjb5RPdLtUaL1OA8bNHtP8WPDPrPPnXjv3nnLv8B4SLay7nGrSCCGH20rsvf/
jdtA0kDv1/fQWOCq/D3FXIkFuquB7e5IffKgDT9O9nFbR43bpI9zbvLhv966c8kF
qKZ3FNc20pzhsJ9lg2d20lbV1eYTV3aVd1l+/X4X1JeN6wCUoq7dwQNwFfeWKpWz
y9xYwjHmSzQ67huW/F/eDcUkV7+rDCfLdW1qsBxhVePs8KX83HIXDCgl91XCJCkw
L/FvXYS81U1rPQwYAfDGFshlJuB1e44hMwS6GwUjgm/UUq+bv445lfsC9vuKR7pg
b9BxcQaXexdj+BRBu/4EDdtYj8lZeWhfNH8LokPXIdohkbywKQK9urHTJA9KLIOe
Py6vSekg26E=
=Ljyz
-----END PGP SIGNATURE-----