RHSA-2011:1409: Moderate: openssl security update

Published Oct 26, 2011
·
Updated

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)and Transport Layer Security (TLS v1) protocols, as well as afull-strength, general purpose cryptography library.An uninitialized variable use flaw was found in OpenSSL. This flaw couldcause an application using the OpenSSL Certificate Revocation List (CRL)checking functionality to incorrectly accept a CRL that has a nextUpdatedate in the past. (CVE-2011-3207)All OpenSSL users should upgrade to these updated packages, which contain abackported patch to resolve this issue. For the update to take effect, allservices linked to the OpenSSL library must be restarted, or the systemrebooted.

Affected Software

10 affected componentsFixes available
redhat/openssl<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-debuginfo<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-debuginfo<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-devel<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-devel<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-perl<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-static<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-perl<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5
redhat/openssl-static<1.0.0-10.el6_1.5
1.0.0-10.el6_1.5

Remediation

Event History

Oct 26, 2011
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2011:1409?

The severity of RHSA-2011:1409 is classified as moderate.

2

How do I fix RHSA-2011:1409?

To fix RHSA-2011:1409, upgrade to OpenSSL version 1.0.0-10.el6_1.5 or later.

3

Which software is affected by RHSA-2011:1409?

RHSA-2011:1409 affects OpenSSL and its associated packages such as openssl-devel and openssl-perl.

4

What is the cause of RHSA-2011:1409?

RHSA-2011:1409 is caused by an uninitialized variable use flaw discovered in OpenSSL.

5

When was the RHSA-2011:1409 vulnerability identified?

The RHSA-2011:1409 vulnerability was identified in the year 2011.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203