MGASA-2014-0012
Dashboard / Vulnerabilities / MGASA-2014-0012
Summary: Updated openssl package fixes security vulnerabilities
Details: Updated openssl packages fix security vulnerabilities: The DTLS retransmission implementation in OpenSSL through 1.0.1e does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context by interfering with packet delivery (CVE-2013-6450). A carefully crafted invalid TLS handshake could crash OpenSSL with a NULL pointer exception. A malicious server could use this flaw to crash a connecting client (CVE-2013-4353).
References: https://advisories.mageia.org/MGASA-2014-0012.html, https://bugs.mageia.org/show_bug.cgi?id=12183, http://www.openssl.org/news/vulnerabilities.html, http://www.debian.org/security/2014/dsa-2833, http://www.debian.org/security/2014/dsa-2837
Affected packages
Package
Name: openssl
Purl: pkg:rpm/mageia/openssl?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
