Synopsis: Moderate: openssl security update
Advisory ID: SLSA-2015:2617-1
Issue Date: 2015-12-14
CVE Numbers: CVE-2015-3194
CVE-2015-3195
CVE-2015-3196
—
A NULL pointer derefernce flaw was found in the way OpenSSL verified
signatures using the RSA PSS algorithm. A remote attacked could possibly
use this flaw to crash a TLS/SSL client using OpenSSL, or a TLS/SSL server
using OpenSSL if it enabled client authentication. (CVE-2015-3194)
A memory leak vulnerability was found in the way OpenSSL parsed PKCS#7 and
CMS data. A remote attacker could use this flaw to cause an application
that parses PKCS#7 or CMS data from untrusted sources to use an excessive
amount of memory and possibly crash. (CVE-2015-3195)
A race condition flaw, leading to a double free, was found in the way
OpenSSL handled pre-shared key (PSK) identify hints. A remote attacker
could use this flaw to crash a multi-threaded SSL/TLS client using
OpenSSL. (CVE-2015-3196)
For the update to take effect, all services linked to the OpenSSL library
must be restarted, or the system rebooted.
—
SL6
x86_64
openssl-1.0.1e-42.el6_7.1.i686.rpm
openssl-1.0.1e-42.el6_7.1.x86_64.rpm
openssl-debuginfo-1.0.1e-42.el6_7.1.i686.rpm
openssl-debuginfo-1.0.1e-42.el6_7.1.x86_64.rpm
openssl-devel-1.0.1e-42.el6_7.1.i686.rpm
openssl-devel-1.0.1e-42.el6_7.1.x86_64.rpm
openssl-perl-1.0.1e-42.el6_7.1.x86_64.rpm
openssl-static-1.0.1e-42.el6_7.1.x86_64.rpm
i386
openssl-1.0.1e-42.el6_7.1.i686.rpm
openssl-debuginfo-1.0.1e-42.el6_7.1.i686.rpm
openssl-devel-1.0.1e-42.el6_7.1.i686.rpm
openssl-perl-1.0.1e-42.el6_7.1.i686.rpm
openssl-static-1.0.1e-42.el6_7.1.i686.rpm
– Scientific Linux Development Team