[USN-5328-2] OpenSSL vulnerability
Severity
High
Affected Packages
8
CVEs
1
OpenSSL could be made to stop responding if it opened a specially crafted certificate.
USN-5328-1 fixed a vulnerability in OpenSSL. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Tavis Ormandy discovered that OpenSSL incorrectly parsed certain
certificates. A remote attacker could possibly use this issue to cause
OpenSSH to stop responding, resulting in a denial of service.
Package | Affected Version |
---|---|
pkg:deb/ubuntu/openssl?distro=xenial | < 1.0.2g-1ubuntu4.20+esm2 |
pkg:deb/ubuntu/openssl?distro=trusty | < 1.0.1f-1ubuntu2.27+esm5 |
pkg:deb/ubuntu/libssl1.0.0?distro=xenial | < 1.0.2g-1ubuntu4.20+esm2 |
pkg:deb/ubuntu/libssl1.0.0?distro=trusty | < 1.0.1f-1ubuntu2.27+esm5 |
pkg:deb/ubuntu/libssl-doc?distro=xenial | < 1.0.2g-1ubuntu4.20+esm2 |
pkg:deb/ubuntu/libssl-doc?distro=trusty | < 1.0.1f-1ubuntu2.27+esm5 |
pkg:deb/ubuntu/libssl-dev?distro=xenial | < 1.0.2g-1ubuntu4.20+esm2 |
pkg:deb/ubuntu/libssl-dev?distro=trusty | < 1.0.1f-1ubuntu2.27+esm5 |
- ID
- USN-5328-2
- Severity
- high
- URL
- https://ubuntu.com/security/notices/USN-5328-2
- Published
-
2022-03-15T18:12:12
(2 years ago) - Modified
-
2022-03-15T18:12:12
(2 years ago) - Other Advisories
-
- ALAS-2022-1575
- ALAS2-2022-1766
- ALAS2-2024-2502
- ALPINE:CVE-2022-0778
- ALSA-2022:1065
- ALSA-2022:5326
- DSA-5103-1
- ELSA-2022-1065
- ELSA-2022-1066
- ELSA-2022-4899
- ELSA-2022-5326
- ELSA-2022-9224
- ELSA-2022-9225
- ELSA-2022-9233
- ELSA-2022-9237
- ELSA-2022-9243
- ELSA-2022-9246
- ELSA-2022-9249
- ELSA-2022-9255
- ELSA-2022-9258
- ELSA-2022-9272
- FEDORA-2022-8bb51f6901
- FEDORA-2022-9e88b5d8d7
- FEDORA-2022-a5f51502f0
- FREEBSD:ADD683BE-BD76-11EC-A06F-D4C9EF517024
- FREEBSD:EA05C456-A4FD-11EC-90DE-1C697AA5A594
- GLSA-202210-02
- GLSA-202405-29
- MS:CVE-2022-0778
- openSUSE-SU-2022:0856-1
- RHSA-2022:1065
- RHSA-2022:1066
- RHSA-2022:4899
- RHSA-2022:5326
- RLSA-2022:1065
- RLSA-2022:4899
- RLSA-2022:5326
- RUSTSEC-2022-0014
- SECADV-20220315-1
- SSA:2022-076-02
- SUSE-SU-2022:0851-1
- SUSE-SU-2022:0853-1
- SUSE-SU-2022:0854-1
- SUSE-SU-2022:0856-1
- SUSE-SU-2022:0857-1
- SUSE-SU-2022:0859-1
- SUSE-SU-2022:0860-1
- SUSE-SU-2022:0861-1
- SUSE-SU-2022:0935-1
- SUSE-SU-2022:1459-1
- SUSE-SU-2022:1461-1
- SUSE-SU-2022:1462-1
- SUSE-SU-2022:1536-1
- USN-5328-1
- USN-6457-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/openssl?distro=xenial | ubuntu | openssl | < 1.0.2g-1ubuntu4.20+esm2 | xenial | ||
Affected | pkg:deb/ubuntu/openssl?distro=trusty | ubuntu | openssl | < 1.0.1f-1ubuntu2.27+esm5 | trusty | ||
Affected | pkg:deb/ubuntu/libssl1.0.0?distro=xenial | ubuntu | libssl1.0.0 | < 1.0.2g-1ubuntu4.20+esm2 | xenial | ||
Affected | pkg:deb/ubuntu/libssl1.0.0?distro=trusty | ubuntu | libssl1.0.0 | < 1.0.1f-1ubuntu2.27+esm5 | trusty | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=xenial | ubuntu | libssl-doc | < 1.0.2g-1ubuntu4.20+esm2 | xenial | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=trusty | ubuntu | libssl-doc | < 1.0.1f-1ubuntu2.27+esm5 | trusty | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=xenial | ubuntu | libssl-dev | < 1.0.2g-1ubuntu4.20+esm2 | xenial | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=trusty | ubuntu | libssl-dev | < 1.0.1f-1ubuntu2.27+esm5 | trusty |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |