[FEDORA-2010-5357] Fedora 11: openssl

Severity High
Affected Packages 1
CVEs 8

Update to upstream version 0.9.8n fixing multiple security issues:
CVE-2009-3555, CVE-2009-3245, CVE-2009-4355, and CVE-2010-0433. Refer to
upstream CHANGES file for the detailed list of changes since version 0.9.8k:
* http://cvs.openssl.org/fileview?f=openssl/CHANGES&v=1.1238.2.193

Package Affected Version
pkg:rpm/fedora/openssl?distro=fedora-11 < 0.9.8n.1.fc11
ID
FEDORA-2010-5357
Severity
high
Severity from
CVE-2009-3245
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2010-5357
Published
2010-04-16T23:49:46
(14 years ago)
Modified
2010-04-16T23:49:46
(14 years ago)
Rights
Copyright 2010 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 570924 Bug #570924 - CVE-2009-3245 openssl: missing bn_wexpand return value checks https://bugzilla.redhat.com/show_bug.cgi?id=570924
Bugzilla 546707 Bug #546707 - CVE-2009-4355 openssl significant memory leak in certain SSLv3 requests (DoS) https://bugzilla.redhat.com/show_bug.cgi?id=546707
Bugzilla 533125 Bug #533125 - CVE-2009-3555 TLS: MITM attacks via session renegotiation https://bugzilla.redhat.com/show_bug.cgi?id=533125
Bugzilla 569774 Bug #569774 - CVE-2010-0433 openssl: crash caused by a missing krb5_sname_to_principal() return value check https://bugzilla.redhat.com/show_bug.cgi?id=569774
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/openssl?distro=fedora-11 fedora openssl < 0.9.8n.1.fc11 fedora-11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...