Fedora Legacy Test Update Notification: openssl095a

Jesse Keating jkeating at j2solutions.net
Mon Mar 22 23:29:03 UTC 2004


---------------------------------------------------------------------
Fedora Test Update Notification
FEDORA-2004-1395
Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=1395
2004-03-22
---------------------------------------------------------------------
 
Name        : openssl095a
Version 7.2 : 0.9.5a-24.7.3.legacy
Version 7.3 : 0.9.5a-24.7.3.legacy
Version 8.0 : 0.9.5a-24.8.legacy
Summary     : The OpenSSL toolkit.
Description :
The OpenSSL toolkit provides support for secure communications between
machines. OpenSSL includes a certificate management tool and shared
libraries which provide various cryptographic algorithms and
protocols.
 
---------------------------------------------------------------------
Update Information:
 
CAN-2003-0851:
OpenSSL 0.9.6k does not properly handle certain ASN.1 sequences. As a 
result, OpenSSL performs a recursive function call that could exhaust 
system resources and crash the process using the OpenSSL library.
   
CAN-2004-0081:
OpenSSL prior to version 0.9.6d does not properly handle unknown message 
types. An attacker could cause the application using OpenSSL to enter 
an infinite loop, resulting in a denial of service.
---------------------------------------------------------------------
Changelog:
 
 
* Thu Mar 18 2004 Jesse Keating <jkeating at j2solutions.net>
 
- 0.9.5a-24.7.3.legacy
- add security fixes for CAN-2004-0081 and CAN-2003-0851
 
---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedoralegacy.org/redhat/

6125c0171b9bd2c49e2f206fa616c70310262085  
7.2/updates-testing/SRPMS/openssl095a-0.9.5a-24.7.3.legacy.src.rpm
fff610245bcd73fce6b78c0e7f4155cf0c627762  
7.2/updates-testing/i386/openssl095a-0.9.5a-24.7.3.legacy.i386.rpm
 
6125c0171b9bd2c49e2f206fa616c70310262085  
7.3/updates-testing/SRPMS/openssl095a-0.9.5a-24.7.3.legacy.src.rpm
fff610245bcd73fce6b78c0e7f4155cf0c627762  
7.3/updates-testing/i386/openssl095a-0.9.5a-24.7.3.legacy.i386.rpm
 
6b789ea67363c4a7f23cc1e1363c32509605d5b4  
8.0/updates-testing/SRPMS/openssl095a-0.9.5a-24.8.legacy.src.rpm
f15faf931188fcc4991cd692eba88ef4dd3e670e  
8.0/updates-testing/i386/openssl095a-0.9.5a-24.8.legacy.i386.rpm
 
Please note that this update is also available via yum and apt
through the updates-testing channel.  Many people find this an easier
way to apply updates.
---------------------------------------------------------------------

-- 
Jesse Keating RHCE      (geek.j2solutions.net)
Fedora Legacy Team      (www.fedoralegacy.org)
GPG Public Key          (geek.j2solutions.net/jkeating.j2solutions.pub)
 
Was I helpful?  Let others know:
 http://svcs.affero.net/rm.php?r=jkeating
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: signature
URL: <http://listman.redhat.com/archives/fedora-legacy-list/attachments/20040322/55e17ed5/attachment.sig>


More information about the fedora-legacy-list mailing list