openssl-1.0.2k-26.0.4.el7.AXS7

エラータID: AXSA:2025-10514:03

リリース日: 
2025/07/17 Thursday - 20:10
題名: 
openssl-1.0.2k-26.0.4.el7.AXS7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
Low
Description: 

The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.

Security Fix(es):

* CVE-2019-1563: fix information disclosure in PKCS7_dataDecode and
CMS_decrypt_set1_pkey

CVE(s):
CVE-2019-1563
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

Asianux Server 7 for x86_64
  1. openssl-1.0.2k-26.0.4.el7.AXS7.x86_64.rpm
    MD5: eb29a3db971776e3bcdfd2d4be8a9966
    SHA-256: 6c3f3cad408f9dc5e2f4b6d6482b5129137a640556c3ada720658df015477a70
    Size: 494.88 kB
  2. openssl-devel-1.0.2k-26.0.4.el7.AXS7.i686.rpm
    MD5: b02bebedb434d8ab744c6758a45d4183
    SHA-256: 138be0a76e0451c6416c7a13615fc21ba66cfe501abe3c81f70d7e362a832a7e
    Size: 1.51 MB
  3. openssl-devel-1.0.2k-26.0.4.el7.AXS7.x86_64.rpm
    MD5: 1ba425396162a5ef129461b07d68c42b
    SHA-256: 1dd7f73988f967a9643748861c281e08f8113b2ba119433364a145fe3a1d7faf
    Size: 1.51 MB
  4. openssl-libs-1.0.2k-26.0.4.el7.AXS7.i686.rpm
    MD5: f2956190ab06d1690cf0c08c8326292b
    SHA-256: 47b417e659c00b278554eb1f11ecb5262bbe4e42a32fb64c510a7f9dda9e2a11
    Size: 0.98 MB
  5. openssl-libs-1.0.2k-26.0.4.el7.AXS7.x86_64.rpm
    MD5: 44da2c1aaa0c06913ef169dee46242c9
    SHA-256: dc9aadff91b1306cdb39716f849a5f3776a1910fc0fd61137cd9bf268ff791a7
    Size: 1.20 MB