openssl-1.0.1e-42.AXS4.2
エラータID: AXSA:2016-008:01
Release date:
Friday, January 8, 2016 - 10:11
Subject:
openssl-1.0.1e-42.AXS4.2
Affected Channels:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
Moderate
Description:
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.
Security issues fixed with this release:
CVE-2015-7575
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
Solution:
Update packages.
CVEs:
CVE-2015-7575
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Additional Info:
N/A
Download:
SRPMS
- openssl-1.0.1e-42.AXS4.2.src.rpm
MD5: 1f45dc472e95911e1e81bdd25737b735
SHA-256: 994022e0f6644e63bbf6e786ffc23461f2c91b97b2b02a3f8ff22bc50f121796
Size: 3.06 MB
Asianux Server 4 for x86
- openssl-1.0.1e-42.AXS4.2.i686.rpm
MD5: 55bfb3a7f6fa330a641412d7684d50d8
SHA-256: 7b692b8d9bb55191eb25d8b20073328c8bfde85b1bf749a6ef0cd3a16e539abc
Size: 1.51 MB - openssl-devel-1.0.1e-42.AXS4.2.i686.rpm
MD5: ea2f5abae35c15f0177a08e415f7b9db
SHA-256: 272430393483d18cd594165263296b9e97f7770374b5c6cc1bfee49f86c92ff0
Size: 1.17 MB
Asianux Server 4 for x86_64
- openssl-1.0.1e-42.AXS4.2.x86_64.rpm
MD5: 70b1ef5b994f775d5f0611e8641a5149
SHA-256: 8ed4ebec3b96c392c4bfd704cfd2a7e253b12db2ca482d4e170f08eb3755e47f
Size: 1.52 MB - openssl-devel-1.0.1e-42.AXS4.2.x86_64.rpm
MD5: 1d09f63ac5dd2a35f66cb604c25e64be
SHA-256: d03fa8c7cb6e4c5cf07ccf2cc497f6e414134b634a2d56e62fa15f31bd553a46
Size: 1.17 MB - openssl-1.0.1e-42.AXS4.2.i686.rpm
MD5: 55bfb3a7f6fa330a641412d7684d50d8
SHA-256: 7b692b8d9bb55191eb25d8b20073328c8bfde85b1bf749a6ef0cd3a16e539abc
Size: 1.51 MB - openssl-devel-1.0.1e-42.AXS4.2.i686.rpm
MD5: ea2f5abae35c15f0177a08e415f7b9db
SHA-256: 272430393483d18cd594165263296b9e97f7770374b5c6cc1bfee49f86c92ff0
Size: 1.17 MB