openssl-1.0.1e-30.AXS4.5
エラータID: AXSA:2015-025:01
Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.
Security issues fixed with this release:
CVE-2014-3570
The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.
CVE-2014-3571
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for the handshake header than for the handshake body, related to the dtls1_get_record function in d1_pkt.c and the ssl3_read_n function in s3_pkt.c.
CVE-2014-3572
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.
CVE-2014-8275
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
CVE-2015-0204
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role.
CVE-2015-0205
The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.
CVE-2015-0206
Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.
Update package.
N/A
SRPMS
- openssl-1.0.1e-30.AXS4.5.src.rpm
MD5: f92b1a039c98854375cf6a17fbed34c9
SHA-256: 1488ffcbdbe0a1a6b22aae9b7a297ed186615988b9993389c5a79f6ad11c21e1
Size: 3.04 MB
Asianux Server 4 for x86
- openssl-1.0.1e-30.AXS4.5.i686.rpm
MD5: b755b25848f1fbd4d560702038f459a0
SHA-256: acbd7eb28b3788dfd8063eda13c02eba1b2cad7aa3f027bfda0dbeeeb14b1283
Size: 1.51 MB - openssl-devel-1.0.1e-30.AXS4.5.i686.rpm
MD5: 4a6891fea0e69fb6ad44e65a355ced5d
SHA-256: 97c4ca93629053dfc77a70ce7072b21916469af8f47ea4d945dc2971b93f3631
Size: 1.17 MB
Asianux Server 4 for x86_64
- openssl-1.0.1e-30.AXS4.5.x86_64.rpm
MD5: dd4e819c1c4a0fe7389c914f27834c80
SHA-256: d85f61db0dae0a7a0b55986031ab9318f1adf265c55970df7cd039335b223ec5
Size: 1.51 MB - openssl-devel-1.0.1e-30.AXS4.5.x86_64.rpm
MD5: 4c3c7bce75a35008cc3ca1a7ad1337df
SHA-256: e9367004b1c9a0232a31010169752e0f0d70c80530f6f054445685fb9b58589a
Size: 1.17 MB - openssl-1.0.1e-30.AXS4.5.i686.rpm
MD5: b755b25848f1fbd4d560702038f459a0
SHA-256: acbd7eb28b3788dfd8063eda13c02eba1b2cad7aa3f027bfda0dbeeeb14b1283
Size: 1.51 MB - openssl-devel-1.0.1e-30.AXS4.5.i686.rpm
MD5: 4a6891fea0e69fb6ad44e65a355ced5d
SHA-256: 97c4ca93629053dfc77a70ce7072b21916469af8f47ea4d945dc2971b93f3631
Size: 1.17 MB