• [SECURITY] [DSA 3287-1] openssl security update

    From Alessandro Ghedini@1:229/2 to All on Sat Jun 13 16:40:02 2015
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3287-1 [email protected] https://www.debian.org/security/ Alessandro Ghedini
    June 13, 2015 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : openssl
    CVE ID : CVE-2014-8176 CVE-2015-1788 CVE-2015-1789 CVE-2015-1790
    CVE-2015-1791 CVE-2015-1792 CVE-2015-4000

    Multiple vulnerabilities were discovered in OpenSSL, a Secure Sockets
    Layer toolkit.

    CVE-2014-8176

    Praveen Kariyanahalli, Ivan Fratric and Felix Groebert discovered
    that an invalid memory free could be triggered when buffering DTLS
    data. This could allow remote attackers to cause a denial of service
    (crash) or potentially execute arbitrary code. This issue only
    affected the oldstable distribution (wheezy).

    CVE-2015-1788

    Joseph Barr-Pixton discovered that an infinite loop could be triggered
    due to incorrect handling of malformed ECParameters structures. This
    could allow remote attackers to cause a denial of service.

    CVE-2015-1789

    Robert Swiecki and Hanno Böck discovered that the X509_cmp_time
    function could read a few bytes out of bounds. This could allow remote
    attackers to cause a denial of service (crash) via crafted
    certificates and CRLs.

    CVE-2015-1790

    Michal Zalewski discovered that the PKCS#7 parsing code did not
    properly handle missing content which could lead to a NULL pointer
    dereference. This could allow remote attackers to cause a denial of
    service (crash) via crafted ASN.1-encoded PKCS#7 blobs.

    CVE-2015-1791

    Emilia Käsper discovered that a race condition could occur due to
    incorrect handling of NewSessionTicket in a multi-threaded client,
    leading to a double free. This could allow remote attackers to cause
    a denial of service (crash).

    CVE-2015-1792

    Johannes Bauer discovered that the CMS code could enter an infinite
    loop when verifying a signedData message, if presented with an
    unknown hash function OID. This could allow remote attackers to cause
    a denial of service.

    Additionally OpenSSL will now reject handshakes using DH parameters
    shorter than 768 bits as a countermeasure against the Logjam attack (CVE-2015-4000).

    For the oldstable distribution (wheezy), these problems have been fixed
    in version 1.0.1e-2+deb7u17.

    For the stable distribution (jessie), these problems have been fixed in
    version 1.0.1k-3+deb8u1.

    For the testing distribution (stretch), these problems have been fixed
    in version 1.0.2b-1.

    For the unstable distribution (sid), these problems have been fixed in
    version 1.0.2b-1.

    We recommend that you upgrade your openssl packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJVfD8XAAoJEK+lG9bN5XPLVMcP/3IJavEP0DvwOjnmmoRMTZ6E gx/OkKjyojIT5+S5nF2NuEnkMXkQkEioOhABedGiREM5441zClA2ahbjXPe+NWsU MTXdVDx0CyWon2aE4vyn9XxD1vyhKffPBozS+WYZlQyB7y1xBD7as1pp40gxn3Ps p9I379gQ/HbKW9GK4E9y/ocXHs9WFXeh9uBEge+N+VQi+t0C8WJZX1LJ4k1Fc5GY /5RpEU6ntJWhQaUxdaVK7Eh7DThnlmoLp5cyxK6daesXrbwS3jyNknk05XphktkG I2IBoZe+Z1Dgm9URqMh6O1amOOzdbc5y9HOwmW457F/ky5DggTlabeOS+Dwo3X6P AzWaRgOizSDyxsdBpDD3QsqZlnWI5dKLy2irvKS6c0N3ju8huwEKRdOYfbFZHA2r x/uW6GFrDhVMcdA5UjvEZoKHmC7aXdaTbLodeVNchx5ARz85OZgfo40StNi09ihC 26peaJNLwls32YwaIoMX9lTJRcKhdOPkvu6ufp8lTCxaYD/B2+T9gCaqUP89KgA2 zo18PGsBHPizKPVg5jRQd7esigsqR+R84FIe13yxytw85oK58awkxkibZl/HldFQ wO7cQlBDm5sKIGLu36A6Qw+ofafk34JPLjSi7xFSxID86S77/z16B/ySB0OvzHvJ AXTWHHGtbZfFFPXAIHeu
    =7M6H
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)