Oracle alert ELSA-2016-0302 (openssl)
| From: | Errata Announcements for Oracle Linux <el-errata@oss.oracle.com> | |
| To: | el-errata@oss.oracle.com | |
| Subject: | [El-errata] ELSA-2016-0302 Important: Oracle Linux 5 openssl security update | |
| Date: | Tue, 01 Mar 2016 15:12:34 -0800 | |
| Message-ID: | <56D621E2.5070503@oracle.com> |
Oracle Linux Security Advisory ELSA-2016-0302 http://linux.oracle.com/errata/ELSA-2016-0302.html The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: openssl-0.9.8e-39.0.1.el5_11.i386.rpm openssl-0.9.8e-39.0.1.el5_11.i686.rpm openssl-devel-0.9.8e-39.0.1.el5_11.i386.rpm openssl-perl-0.9.8e-39.0.1.el5_11.i386.rpm x86_64: openssl-0.9.8e-39.0.1.el5_11.i686.rpm openssl-0.9.8e-39.0.1.el5_11.x86_64.rpm openssl-devel-0.9.8e-39.0.1.el5_11.i386.rpm openssl-devel-0.9.8e-39.0.1.el5_11.x86_64.rpm openssl-perl-0.9.8e-39.0.1.el5_11.x86_64.rpm ia64: openssl-0.9.8e-39.0.1.el5_11.i686.rpm openssl-0.9.8e-39.0.1.el5_11.ia64.rpm openssl-devel-0.9.8e-39.0.1.el5_11.ia64.rpm openssl-perl-0.9.8e-39.0.1.el5_11.ia64.rpm SRPMS: http://oss.oracle.com/ol5/SRPMS-updates/openssl-0.9.8e-39... Description of changes: [0.9.8e-39.0.1] - To disable SSLv2 client connections create the file /etc/sysconfig/openssl-ssl-client-kill-sslv2 (John Haxby) [orabug 21673934] - Backport openssl 08-Jan-2015 security fixes (John Haxby) [orabug 20409893] - fix CVE-2014-3570 - Bignum squaring may produce incorrect results - fix CVE-2014-3571 - DTLS segmentation fault in dtls1_get_record - fix CVE-2014-3572 - ECDHE silently downgrades to ECDH [Client] [0.9.8e-39] - fix CVE-2016-0797 - heap corruption in BN_hex2bn and BN_dec2bn [0.9.8e-38] - fix CVE-2015-3197 - SSLv2 ciphersuite enforcement - disable SSLv2 in the generic TLS method (can be reenabled by setting environment variable OPENSSL_ENABLE_SSL2) _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata
