LWN.net Logo

Oracle alert ELSA-2013-0587 (openssl)

From:  Errata Announcements for Oracle Linux <el-errata@oss.oracle.com>
To:  el-errata@oss.oracle.com
Subject:  [El-errata] ELSA-2013-0587 Moderate: Oracle Linux 6 openssl security update
Date:  Mon, 04 Mar 2013 23:12:58 -0800
Message-ID:  <51359AFA.2070400@oracle.com>
Archive-link:  Article, Thread

Oracle Linux Security Advisory ELSA-2013-0587 https://rhn.redhat.com/errata/RHSA-2013-0587.html The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: i386: openssl-1.0.0-27.el6_4.2.i686.rpm openssl-devel-1.0.0-27.el6_4.2.i686.rpm openssl-perl-1.0.0-27.el6_4.2.i686.rpm openssl-static-1.0.0-27.el6_4.2.i686.rpm x86_64: openssl-1.0.0-27.el6_4.2.i686.rpm openssl-1.0.0-27.el6_4.2.x86_64.rpm openssl-devel-1.0.0-27.el6_4.2.i686.rpm openssl-devel-1.0.0-27.el6_4.2.x86_64.rpm openssl-perl-1.0.0-27.el6_4.2.x86_64.rpm openssl-static-1.0.0-27.el6_4.2.x86_64.rpm SRPMS: http://oss.oracle.com/ol6/SRPMS-updates/openssl-1.0.0-27.... Description of changes: [1.0.0-27.2] - fix for CVE-2013-0169 - SSL/TLS CBC timing attack (#907589) - fix for CVE-2013-0166 - DoS in OCSP signatures checking (#908052) - enable compression only if explicitly asked for or OPENSSL_DEFAULT_ZLIB environment variable is set (fixes CVE-2012-4929 #857051) - use __secure_getenv() everywhere instead of getenv() (#839735) _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds