openssl-0.9.8e-22.AXS3.1

エラータID: AXSA:2012-465:03

Release date: 
Sunday, April 1, 2012 - 14:30
Subject: 
openssl-0.9.8e-22.AXS3.1
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols.

Security issues fixed this release:

• CVE-2012-0884
The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Million Message Attack (MMA) adaptive chosen ciphertext attack.

• CVE-2012-1165
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.

Fixed bugs:

• Fixed a regression which caused Server Gated Cryptography (SGC) handshakes to fail.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. openssl-0.9.8e-22.AXS3.1.src.rpm
    MD5: 3a9433b409bd56db2715d87e278fc63f
    SHA-256: fc1b2b228f83dddc0bc586745ea3e0e7be650cb5eb93bff567420de14f6fe1d9
    Size: 3.13 MB

Asianux Server 3 for x86
  1. openssl-0.9.8e-22.AXS3.1.i386.rpm
    MD5: 124b50ffae7b0dcd4fd114febb2b8d37
    SHA-256: 2df264d14f5f49772df6e78092a6e70a6f3134104f334c7ffc70557d0382d6f4
    Size: 1.46 MB
  2. openssl-0.9.8e-22.AXS3.1.i686.rpm
    MD5: 5d43d80585f59482d80cf9d12ccdf3db
    SHA-256: 51eb3815c55345e6e1b8276c5b74dcc4297961f9abff67a86d7e84d892791e12
    Size: 1.45 MB
  3. openssl-devel-0.9.8e-22.AXS3.1.i386.rpm
    MD5: d6983160d1825f40023058d7e34206ca
    SHA-256: b3e26d3df8eaab4031ee0c075ebd0d38a4fd48df3ef38cae8f20bee13e5b1983
    Size: 1.90 MB
  4. openssl-perl-0.9.8e-22.AXS3.1.i386.rpm
    MD5: 94032d40edc472e31246260d1e36934d
    SHA-256: 125e31bcc3f3d8795409af5233118d65798d85243b7366f890923ece17aa3dfb
    Size: 36.37 kB

Asianux Server 3 for x86_64
  1. openssl-0.9.8e-22.AXS3.1.x86_64.rpm
    MD5: 3aa6bcedf1966de454a5db06f9a4bd4b
    SHA-256: efe9926112b49065732a84c2f01735d302167598e1d42e42c799febbaa77c80a
    Size: 1.45 MB
  2. openssl-devel-0.9.8e-22.AXS3.1.x86_64.rpm
    MD5: 9aa88b9a3305ea43c4c5b5dcece815a6
    SHA-256: 58e925c737ab884e5682643811420776701af0ae1da213b49a7b32497a96e70d
    Size: 1.88 MB
  3. openssl-perl-0.9.8e-22.AXS3.1.x86_64.rpm
    MD5: af5258bfae2caefb0c9a0e1b9f5b28cc
    SHA-256: e2b472a5b2102af32a9e255288ab3f3324b1b485a73f2acb036a2b73153da0ab
    Size: 36.32 kB