| From: |
| Conectiva Updates <secure@conectiva.com.br> |
| To: |
| conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net,
bugtraq@securityfocus.com, security-alerts@linuxsecurity.com,
linsec@lists.seifried.org |
| Subject: |
| [CLA-2003:759] Conectiva Security Announcement - openssl |
| Date: |
| Fri, 3 Oct 2003 16:36:33 -0300 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- --------------------------------------------------------------------------
PACKAGE : openssl
SUMMARY : Denial of service vulnerability
DATE : 2003-10-03 16:30:00
ID : CLA-2003:759
RELEVANT
RELEASES : 7.0, 8
- -------------------------------------------------------------------------
DESCRIPTION
OpenSSL[1] implements the Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as full-strength
general purpose cryptography functions. It is used (as a library) by
several projects, like Apache, OpenSSH, Bind, OpenLDAP and many
others clients and servers programs.
Patrick Hornick reported[2] a denial of service vulnerability in
OpenSSL versions prior to 0.9.6f. An attacker can contruct a
specially crafted SSLv2 CLIENT_MASTER_KEY message that when parsed by
a program using OpenSSL can trigger a call to the die() function,
which aborts the program as an attempt to mitigate the exploitation
of potential parsing errors.
This update includes patches that remove the calls to die() and
replaces them with error reporting/treatment (as in new version of
OpenSSL), thus avoiding the closing of applications when receiving
such malicious messages.
Please note that this issue has no direct relation with the recently
fixed vulnerabilities[3] in the OpenSSL ASN.1 parsing code.
SOLUTION
It is recommended that all users upgrade their openssl packages.
Please note that it is necessary to restart services which use the
library (such as the apache web server with SSL enabled) so that the
new, fixed, version is used. A list of such applications can be
obtained after the upgrade with the following command:
lsof | grep libssl
The first column will contain the name of the application that needs
to be restarted. If there is any doubt about which application has to
be restarted or how to do it, we recommend that the system be
rebooted.
REFERENCES
1.http://www.openssl.org
2.http://www.ebitech.sk/patrik/SA/SA-20031002.txt
3.http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000751&idioma=en
UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-0.9.6a-3U70_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-devel-0.9.6a-3U70_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-devel-static-0.9.6a-3U70_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/openssl-progs-0.9.6a-3U70_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/openssl-0.9.6a-3U70_8cl.src.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-0.9.6c-2U80_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-devel-0.9.6c-2U80_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-devel-static-0.9.6c-2U80_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/openssl-progs-0.9.6c-2U80_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/SRPMS/openssl-0.9.6c-2U80_7cl.src.rpm
ADDITIONAL INSTRUCTIONS
The apt tool can be used to perform RPM packages upgrades:
- run: apt-get update
- after that, execute: apt-get upgrade
Detailed instructions reagarding the use of apt and upgrade examples
can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en
- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en
- -------------------------------------------------------------------------
Copyright (c) 2003 Conectiva Inc.
http://www.conectiva.com
- -------------------------------------------------------------------------
subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE/fc/A42jd0JmAcZARAjx5AKCGfaQ1JkRDNyLows5PDLKrHRG38ACfTS9G
sghoSWNf/iumiXOOofZMgpY=
=fvNW
-----END PGP SIGNATURE-----
(
Log in to post comments)