what you don't know can hurt you

Debian Security Advisory 3197-1

Debian Security Advisory 3197-1
Posted Mar 20, 2015
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3197-1 - Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292
MD5 | 81d2834847d1995a892ad45b8b801880

Debian Security Advisory 3197-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3197-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
March 19, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : openssl
CVE ID : CVE-2015-0209 CVE-2015-0286 CVE-2015-0287 CVE-2015-0288
CVE-2015-0289 CVE-2015-0292

Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit. The Common Vulnerabilities and Exposures project
identifies the following issues:

CVE-2015-0286

Stephen Henson discovered that the ASN1_TYPE_cmp() function
can be crashed, resulting in denial of service.

CVE-2015-0287

Emilia Kaesper discovered a memory corruption in ASN.1 parsing.

CVE-2015-0289

Michal Zalewski discovered a NULL pointer dereference in the
PKCS#7 parsing code, resulting in denial of service.

CVE-2015-0292

It was discovered that missing input sanitising in base64 decoding
might result in memory corruption.

CVE-2015-0209

It was discovered that a malformed EC private key might result in
memory corruption.

CVE-2015-0288

It was discovered that missing input sanitising in the
X509_to_X509_REQ() function might result in denial of service.

For the stable distribution (wheezy), these problems have been fixed in
version 1.0.1e-2+deb7u15. In this update the export ciphers are removed
from the default cipher list.

We recommend that you upgrade your openssl packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJVCt2DAAoJEAVMuPMTQ89EzdAQAICVkSZXyA85zQI9ZDjhyGfB
FF0Di90ogAU/rwzkdlHvu/1HRjQo0VXx9LqYt15Sd4T4enGuswzst1saTu0sNAFZ
x+HtJimu0UyR5EfJ8cUtUNXEGeMFxv381ir0w8/bPF6zin4mu26ywmVwtqPrVTd+
OxvSMgY98glNgkBEcrrQ4juWmy0tHC+Y55jZt7TShDG9MshGgCOS2UZgGW2jiYUA
8BG26LaOHgVfwskPWV5tAEZDDA5heEgLtnCzPHFsAKFiA7ogkExnId5HVfl+Myoe
9MlvlWhp08GMsaaQ7S7T0jvAcHgFYxBIXVpKNqpRv9ah8JfGJ2+Rdj6SFGlTFSgu
ge0uVQgQdt7ebTFKsz/Ema8v72SUT4ysPzIelrUfmI/yZsmCAoE11bQzq0RrC3xJ
e1yfIatghsN4A/Lcai4Dwe1QTLjBwtnKmiUUS5p/LQQ4bM1HHYWo8OIif6RhVDnB
DJEzBYUK3ikJcmEPza3uhvxhd3n+mx2K9tVIYH3bZWmxQ3u0lgr3vhwihYkCdjoR
eaH9ax8xnAdYa2vnZXz6sNvH7DUJoL8zqz9zlfEOsm1DPriXguvDsawS6675RsCs
wJ2bp1NB0qr5uBr0ARfCB7/KSkg9qy4G5A1BVLfvKZnmcnwGUoXCs3JFeriUx5wH
3c95sIClcztatqh+oIVP
=CfMI
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2021

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    17 Files
  • 2
    Apr 2nd
    2 Files
  • 3
    Apr 3rd
    2 Files
  • 4
    Apr 4th
    0 Files
  • 5
    Apr 5th
    15 Files
  • 6
    Apr 6th
    15 Files
  • 7
    Apr 7th
    20 Files
  • 8
    Apr 8th
    16 Files
  • 9
    Apr 9th
    5 Files
  • 10
    Apr 10th
    0 Files
  • 11
    Apr 11th
    0 Files
  • 12
    Apr 12th
    4 Files
  • 13
    Apr 13th
    15 Files
  • 14
    Apr 14th
    27 Files
  • 15
    Apr 15th
    19 Files
  • 16
    Apr 16th
    7 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close