what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 3197-1

Debian Security Advisory 3197-1
Posted Mar 20, 2015
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3197-1 - Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292
SHA-256 | 502c16249125d36a8fc3440e578ad58b60a94b321161f560450e2beedb6e3d38

Debian Security Advisory 3197-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3197-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
March 19, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : openssl
CVE ID : CVE-2015-0209 CVE-2015-0286 CVE-2015-0287 CVE-2015-0288
CVE-2015-0289 CVE-2015-0292

Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit. The Common Vulnerabilities and Exposures project
identifies the following issues:

CVE-2015-0286

Stephen Henson discovered that the ASN1_TYPE_cmp() function
can be crashed, resulting in denial of service.

CVE-2015-0287

Emilia Kaesper discovered a memory corruption in ASN.1 parsing.

CVE-2015-0289

Michal Zalewski discovered a NULL pointer dereference in the
PKCS#7 parsing code, resulting in denial of service.

CVE-2015-0292

It was discovered that missing input sanitising in base64 decoding
might result in memory corruption.

CVE-2015-0209

It was discovered that a malformed EC private key might result in
memory corruption.

CVE-2015-0288

It was discovered that missing input sanitising in the
X509_to_X509_REQ() function might result in denial of service.

For the stable distribution (wheezy), these problems have been fixed in
version 1.0.1e-2+deb7u15. In this update the export ciphers are removed
from the default cipher list.

We recommend that you upgrade your openssl packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJVCt2DAAoJEAVMuPMTQ89EzdAQAICVkSZXyA85zQI9ZDjhyGfB
FF0Di90ogAU/rwzkdlHvu/1HRjQo0VXx9LqYt15Sd4T4enGuswzst1saTu0sNAFZ
x+HtJimu0UyR5EfJ8cUtUNXEGeMFxv381ir0w8/bPF6zin4mu26ywmVwtqPrVTd+
OxvSMgY98glNgkBEcrrQ4juWmy0tHC+Y55jZt7TShDG9MshGgCOS2UZgGW2jiYUA
8BG26LaOHgVfwskPWV5tAEZDDA5heEgLtnCzPHFsAKFiA7ogkExnId5HVfl+Myoe
9MlvlWhp08GMsaaQ7S7T0jvAcHgFYxBIXVpKNqpRv9ah8JfGJ2+Rdj6SFGlTFSgu
ge0uVQgQdt7ebTFKsz/Ema8v72SUT4ysPzIelrUfmI/yZsmCAoE11bQzq0RrC3xJ
e1yfIatghsN4A/Lcai4Dwe1QTLjBwtnKmiUUS5p/LQQ4bM1HHYWo8OIif6RhVDnB
DJEzBYUK3ikJcmEPza3uhvxhd3n+mx2K9tVIYH3bZWmxQ3u0lgr3vhwihYkCdjoR
eaH9ax8xnAdYa2vnZXz6sNvH7DUJoL8zqz9zlfEOsm1DPriXguvDsawS6675RsCs
wJ2bp1NB0qr5uBr0ARfCB7/KSkg9qy4G5A1BVLfvKZnmcnwGUoXCs3JFeriUx5wH
3c95sIClcztatqh+oIVP
=CfMI
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close