Scientific Linux alert SLSA-2016:1137-1 (openssl)
| From: | Pat Riehecky <riehecky@fnal.gov> | |
| To: | <scientific-linux-errata@listserv.fnal.gov> | |
| Subject: | Security ERRATA Important: openssl on SL5.x i386/x86_64 | |
| Date: | Tue, 31 May 2016 16:26:36 +0000 | |
| Message-ID: | <20160531162636.11366.29367@slpackages.fnal.gov> |
Synopsis: Important: openssl security update Advisory ID: SLSA-2016:1137-1 Issue Date: 2016-05-31 CVE Numbers: CVE-2016-2108 -- Security Fix(es): * A flaw was found in the way OpenSSL encoded certain ASN.1 data structures. An attacker could use this flaw to create a specially crafted certificate which, when verified or re-encoded by OpenSSL, could cause it to crash, or execute arbitrary code using the permissions of the user running an application compiled against the OpenSSL library. (CVE-2016-2108) -- SL5 x86_64 openssl-0.9.8e-40.el5_11.i686.rpm openssl-0.9.8e-40.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm openssl-debuginfo-0.9.8e-40.el5_11.x86_64.rpm openssl-perl-0.9.8e-40.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.x86_64.rpm i386 openssl-0.9.8e-40.el5_11.i386.rpm openssl-0.9.8e-40.el5_11.i686.rpm openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm openssl-perl-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.i386.rpm - Scientific Linux Development Team
