openssl-1.0.1e-30.AXS4.5

エラータID: AXSA:2015-025:01

Release date: 
Thursday, January 29, 2015 - 18:10
Subject: 
openssl-1.0.1e-30.AXS4.5
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
Moderate
Description: 

Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.

Security issues fixed with this release:

CVE-2014-3570
The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.

CVE-2014-3571
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for the handshake header than for the handshake body, related to the dtls1_get_record function in d1_pkt.c and the ssl3_read_n function in s3_pkt.c.

CVE-2014-3572
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.

CVE-2014-8275
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.

CVE-2015-0204
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role.

CVE-2015-0205
The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

CVE-2015-0206
Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.

Solution: 

Update package.

Additional Info: 

N/A

Download: 

SRPMS
  1. openssl-1.0.1e-30.AXS4.5.src.rpm
    MD5: f92b1a039c98854375cf6a17fbed34c9
    SHA-256: 1488ffcbdbe0a1a6b22aae9b7a297ed186615988b9993389c5a79f6ad11c21e1
    Size: 3.04 MB

Asianux Server 4 for x86
  1. openssl-1.0.1e-30.AXS4.5.i686.rpm
    MD5: b755b25848f1fbd4d560702038f459a0
    SHA-256: acbd7eb28b3788dfd8063eda13c02eba1b2cad7aa3f027bfda0dbeeeb14b1283
    Size: 1.51 MB
  2. openssl-devel-1.0.1e-30.AXS4.5.i686.rpm
    MD5: 4a6891fea0e69fb6ad44e65a355ced5d
    SHA-256: 97c4ca93629053dfc77a70ce7072b21916469af8f47ea4d945dc2971b93f3631
    Size: 1.17 MB

Asianux Server 4 for x86_64
  1. openssl-1.0.1e-30.AXS4.5.x86_64.rpm
    MD5: dd4e819c1c4a0fe7389c914f27834c80
    SHA-256: d85f61db0dae0a7a0b55986031ab9318f1adf265c55970df7cd039335b223ec5
    Size: 1.51 MB
  2. openssl-devel-1.0.1e-30.AXS4.5.x86_64.rpm
    MD5: 4c3c7bce75a35008cc3ca1a7ad1337df
    SHA-256: e9367004b1c9a0232a31010169752e0f0d70c80530f6f054445685fb9b58589a
    Size: 1.17 MB
  3. openssl-1.0.1e-30.AXS4.5.i686.rpm
    MD5: b755b25848f1fbd4d560702038f459a0
    SHA-256: acbd7eb28b3788dfd8063eda13c02eba1b2cad7aa3f027bfda0dbeeeb14b1283
    Size: 1.51 MB
  4. openssl-devel-1.0.1e-30.AXS4.5.i686.rpm
    MD5: 4a6891fea0e69fb6ad44e65a355ced5d
    SHA-256: 97c4ca93629053dfc77a70ce7072b21916469af8f47ea4d945dc2971b93f3631
    Size: 1.17 MB