|
|
Log in / Subscribe / Register

openssl: multiple vulnerabilities

Package(s):openssl CVE #(s):CVE-2016-0702 CVE-2016-0705 CVE-2016-0797 CVE-2016-0798 CVE-2016-0799
Created:March 1, 2016 Updated:March 14, 2016
Description: From the Debian advisory:

CVE-2016-0702: Yuval Yarom from the University of Adelaide and NICTA, Daniel Genkin from Technion and Tel Aviv University, and Nadia Heninger from the University of Pennsylvania discovered a side-channel attack which makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture. This could allow local attackers to recover RSA private keys.

CVE-2016-0705: Adam Langley from Google discovered a double free bug when parsing malformed DSA private keys. This could allow remote attackers to cause a denial of service or memory corruption in applications parsing DSA private keys received from untrusted sources.

CVE-2016-0797: Guido Vranken discovered an integer overflow in the BN_hex2bn and BN_dec2bn functions that can lead to a NULL pointer dereference and heap corruption. This could allow remote attackers to cause a denial of service or memory corruption in applications processing hex or dec data received from untrusted sources.

CVE-2016-0798: Emilia Käsper of the OpenSSL development team discovered a memory leak in the SRP database lookup code. To mitigate the memory leak, the seed handling in SRP_VBASE_get_by_user is now disabled even if the user has configured a seed. Applications are advised to migrate to the SRP_VBASE_get1_by_user function.

CVE-2016-0799: Guido Vranken discovered an integer overflow in the BIO_*printf functions that could lead to an OOB read when printing very long strings. Additionally the internal doapr_outch function can attempt to write to an arbitrary memory location in the event of a memory allocation failure. These issues will only occur on platforms where sizeof(size_t) > sizeof(int) like many 64 bit systems. This could allow remote attackers to cause a denial of service or memory corruption in applications that pass large amounts of untrusted data to the BIO_*printf functions.

Additionally the EXPORT and LOW ciphers were disabled since they could be used as part of the DROWN (CVE-2016-0800) and SLOTH (CVE-2015-7575) attacks, but note that the oldstable (wheezye) and stable (jessie) distributions are not affected by those attacks since the SSLv2 protocol has already been dropped in the openssl package version 1.0.0c-2.

Alerts:
Red Hat RHSA-2016:2073-01 openssl 2016-10-18
Oracle ELSA-2016-3576 openssl 2016-06-21
openSUSE openSUSE-SU-2016:1566-1 nodejs 2016-06-14
Scientific Linux SLSA-2016:0996-1 openssl 2016-06-08
Fedora FEDORA-2016-e1234b65a2 mingw-openssl 2016-05-21
SUSE SUSE-SU-2016:1360-1 openssl 2016-05-19
openSUSE openSUSE-SU-2016:1332-1 mysql-community-server 2016-05-18
Fedora FEDORA-2016-1aaf308de4 community-mysql 2016-05-16
Fedora FEDORA-2016-7c48036d73 community-mysql 2016-05-15
SUSE SUSE-SU-2016:1290-1 openssl 2016-05-12
openSUSE openSUSE-SU-2016:1273-1 compat-openssl098 2016-05-11
Red Hat RHSA-2016:0996-01 openssl 2016-05-10
SUSE SUSE-SU-2016:1267-1 compat-openssl098 2016-05-09
Scientific Linux SLSA-2016:0722-1 openssl 2016-05-09
Oracle ELSA-2016-0722 openssl 2016-05-09
CentOS CESA-2016:0722 openssl 2016-05-09
Red Hat RHSA-2016:0722-01 openssl 2016-05-09
openSUSE openSUSE-SU-2016:1242-1 libopenssl0_9_8 2016-05-05
openSUSE openSUSE-SU-2016:1239-1 libopenssl0_9_8 2016-05-05
openSUSE openSUSE-SU-2016:1241-1 libopenssl0_9_8 2016-05-05
SUSE SUSE-SU-2016:1057-1 openssl 2016-04-15
Gentoo 201603-15 openssl 2016-03-20
SUSE SUSE-SU-2016:0786-1 sles12-docker-image 2016-03-16
SUSE SUSE-SU-2016:0778-1 sles11sp4-docker-image 2016-03-15
SUSE SUSE-SU-2016:0748-1 sles12sp1-docker-image 2016-03-14
Fedora FEDORA-2016-e6807b3394 openssl 2016-03-13
openSUSE openSUSE-SU-2016:0720-1 openssl 2016-03-11
SUSE SUSE-SU-2016:0678-1 OpenSSL 2016-03-07
Arch Linux ASA-201603-2 openssl 2016-03-07
Arch Linux ASA-201603-3 lib32-openssl 2016-03-07
Fedora FEDORA-2016-2802690366 openssl 2016-03-03
SUSE SUSE-SU-2016:0641-1 openssl 2016-03-03
SUSE SUSE-SU-2016:0631-1 compat-openssl097g 2016-03-02
Slackware SSA:2016-062-02 openssl 2016-03-02
openSUSE openSUSE-SU-2016:0638-1 openssl 2016-03-02
openSUSE openSUSE-SU-2016:0637-1 openssl 2016-03-02
openSUSE openSUSE-SU-2016:0640-1 libopenssl0_9_8 2016-03-03
Mageia MGASA-2016-0093 openssl 2016-03-02
SUSE SUSE-SU-2016:0621-1 openssl 2016-03-01
SUSE SUSE-SU-2016:0624-1 openssl 2016-03-01
SUSE SUSE-SU-2016:0617-1 openssl 2016-03-01
SUSE SUSE-SU-2016:0620-1 openssl 2016-03-01
Scientific Linux SLSA-2016:0302-1 openssl 2016-03-01
Scientific Linux SLSA-2016:0301-1 openssl 2016-03-01
Oracle ELSA-2016-0302 openssl 2016-03-01
Oracle ELSA-2016-0301 openssl 2016-03-01
Oracle ELSA-2016-0301 openssl 2016-03-01
openSUSE openSUSE-SU-2016:0627-1 openssl 2016-03-02
openSUSE openSUSE-SU-2016:0628-1 openssl 2016-03-02
CentOS CESA-2016:0302 openssl 2016-03-01
CentOS CESA-2016:0301 openssl 2016-03-01
Red Hat RHSA-2016:0302-01 openssl 2016-03-01
Red Hat RHSA-2016:0301-01 openssl 2016-03-01
Ubuntu USN-2914-1 openssl 2016-03-01
CentOS CESA-2016:0301 openssl 2016-03-01
Debian DSA-3500-1 openssl 2016-03-01

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds