Gentoo Archives: gentoo-announce

From: Tobias Heinlein <keytoaster@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201110-01 ] OpenSSL: Multiple vulnerabilities
Date: Sun, 09 Oct 2011 15:46:50
Message-Id: 4E91BF97.7060405@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201110-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: OpenSSL: Multiple vulnerabilities
9 Date: October 09, 2011
10 Bugs: #303739, #308011, #322575, #332027, #345767, #347623,
11 #354139, #382069
12 ID: 201110-01
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 Multiple vulnerabilities were found in OpenSSL, allowing for the
20 execution of arbitrary code and other attacks.
21
22 Background
23 ==========
24
25 OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
26 (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general
27 purpose cryptography library.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 dev-libs/openssl < 1.0.0e >= 1.0.0e
36
37 Description
38 ===========
39
40 Multiple vulnerabilities have been discovered in OpenSSL. Please review
41 the CVE identifiers referenced below for details.
42
43 Impact
44 ======
45
46 A context-dependent attacker could cause a Denial of Service, possibly
47 execute arbitrary code, bypass intended key requirements, force the
48 downgrade to unintended ciphers, bypass the need for knowledge of
49 shared secrets and successfully authenticate, bypass CRL validation, or
50 obtain sensitive information in applications that use OpenSSL.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 All OpenSSL users should upgrade to the latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.0.0e"
64
65 NOTE: This is a legacy GLSA. Updates for all affected architectures are
66 available since September 17, 2011. It is likely that your system is
67 already no longer affected by most of these issues.
68
69 References
70 ==========
71
72 [ 1 ] CVE-2009-3245
73 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3245
74 [ 2 ] CVE-2009-4355
75 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4355
76 [ 3 ] CVE-2010-0433
77 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0433
78 [ 4 ] CVE-2010-0740
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0740
80 [ 5 ] CVE-2010-0742
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0742
82 [ 6 ] CVE-2010-1633
83 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1633
84 [ 7 ] CVE-2010-2939
85 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2939
86 [ 8 ] CVE-2010-3864
87 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3864
88 [ 9 ] CVE-2010-4180
89 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4180
90 [ 10 ] CVE-2010-4252
91 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4252
92 [ 11 ] CVE-2011-0014
93 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0014
94 [ 12 ] CVE-2011-3207
95 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3207
96 [ 13 ] CVE-2011-3210
97 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3210
98
99 Availability
100 ============
101
102 This GLSA and any updates to it are available for viewing at
103 the Gentoo Security Website:
104
105 http://security.gentoo.org/glsa/glsa-201110-01.xml
106
107 Concerns?
108 =========
109
110 Security is a primary focus of Gentoo Linux and ensuring the
111 confidentiality and security of our users' machines is of utmost
112 importance to us. Any security concerns should be addressed to
113 security@g.o or alternatively, you may file a bug at
114 https://bugs.gentoo.org.
115
116 License
117 =======
118
119 Copyright 2011 Gentoo Foundation, Inc; referenced text
120 belongs to its owner(s).
121
122 The contents of this document are licensed under the
123 Creative Commons - Attribution / Share Alike license.
124
125 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature