Gentoo Archives: gentoo-announce

From: Chris Reffett <creffett@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201312-03 ] OpenSSL: Multiple Vulnerabilities
Date: Tue, 03 Dec 2013 04:21:53
Message-Id: 529D5A4C.3060706@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201312-03
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: OpenSSL: Multiple Vulnerabilities
9 Date: December 03, 2013
10 Bugs: #369753, #406199, #412643, #415435, #455592
11 ID: 201312-03
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in OpenSSL allowing remote
19 attackers to determine private keys or cause a Denial of Service.
20
21 Background
22 ==========
23
24 OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
25 (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general
26 purpose cryptography library.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 dev-libs/openssl < 1.0.0i *>= 0.9.8y
35 *>= 1.0.0j
36 2 dev-libs/openssl < 0.9.8y Vulnerable!
37 -------------------------------------------------------------------
38 NOTE: Certain packages are still vulnerable. Users should migrate
39 to another package if one is available or wait for the
40 existing packages to be marked stable by their
41 architecture maintainers.
42 -------------------------------------------------------------------
43 2 affected packages
44
45 Description
46 ===========
47
48 Multiple vulnerabilities have been discovered in OpenSSL. Please review
49 the CVE identifiers referenced below for details.
50
51 Impact
52 ======
53
54 Remote attackers can determine private keys, decrypt data, cause a
55 Denial of Service or possibly have other unspecified impact.
56
57 Workaround
58 ==========
59
60 There is no known workaround at this time.
61
62 Resolution
63 ==========
64
65 All OpenSSL 1.0.x users should upgrade to the latest version:
66
67 # emerge --sync
68 # emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.0.0j"
69
70 All OpenSSL 0.9.8 users should upgrade to the latest version:
71
72 # emerge --sync
73 # emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.8y"
74
75 References
76 ==========
77
78 [ 1 ] CVE-2006-7250
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-7250
80 [ 2 ] CVE-2011-1945
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1945
82 [ 3 ] CVE-2012-0884
83 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0884
84 [ 4 ] CVE-2012-1165
85 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1165
86 [ 5 ] CVE-2012-2110
87 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2110
88 [ 6 ] CVE-2012-2333
89 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2333
90 [ 7 ] CVE-2012-2686
91 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2686
92 [ 8 ] CVE-2013-0166
93 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0166
94 [ 9 ] CVE-2013-0169
95 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0169
96
97 Availability
98 ============
99
100 This GLSA and any updates to it are available for viewing at
101 the Gentoo Security Website:
102
103 http://security.gentoo.org/glsa/glsa-201312-03.xml
104
105 Concerns?
106 =========
107
108 Security is a primary focus of Gentoo Linux and ensuring the
109 confidentiality and security of our users' machines is of utmost
110 importance to us. Any security concerns should be addressed to
111 security@g.o or alternatively, you may file a bug at
112 https://bugs.gentoo.org.
113
114 License
115 =======
116
117 Copyright 2013 Gentoo Foundation, Inc; referenced text
118 belongs to its owner(s).
119
120 The contents of this document are licensed under the
121 Creative Commons - Attribution / Share Alike license.
122
123 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature