openssl (SL5)

Synopsis: Important: openssl security update
Advisory ID: SLSA-2016:1137-1
Issue Date: 2016-05-31
CVE Numbers: CVE-2016-2108

Security Fix(es):

* A flaw was found in the way OpenSSL encoded certain ASN.1 data
structures. An attacker could use this flaw to create a specially crafted
certificate which, when verified or re-encoded by OpenSSL, could cause it
to crash, or execute arbitrary code using the permissions of the user
running an application compiled against the OpenSSL library.
(CVE-2016-2108)

SL5
x86_64
openssl-0.9.8e-40.el5_11.i686.rpm
openssl-0.9.8e-40.el5_11.x86_64.rpm
openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm
openssl-debuginfo-0.9.8e-40.el5_11.x86_64.rpm
openssl-perl-0.9.8e-40.el5_11.x86_64.rpm
openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm
openssl-devel-0.9.8e-40.el5_11.i386.rpm
openssl-devel-0.9.8e-40.el5_11.x86_64.rpm
i386
openssl-0.9.8e-40.el5_11.i386.rpm
openssl-0.9.8e-40.el5_11.i686.rpm
openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm
openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm
openssl-perl-0.9.8e-40.el5_11.i386.rpm
openssl-devel-0.9.8e-40.el5_11.i386.rpm

– Scientific Linux Development Team