RHSA-2015:0715: Moderate: openssl security update

Published Mar 23, 2015
·
Updated

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)and Transport Layer Security (TLS v1) protocols, as well as afull-strength, general purpose cryptography library.An invalid pointer use flaw was found in OpenSSL's ASN1TYPEcmp()function. A remote attacker could crash a TLS/SSL client or server usingOpenSSL via a specially crafted X.509 certificate when theattacker-supplied certificate was verified by the application.(CVE-2015-0286)An integer underflow flaw, leading to a buffer overflow, was found in theway OpenSSL decoded malformed Base64-encoded inputs. An attacker able tomake an application using OpenSSL decode a specially crafted Base64-encodedinput (such as a PEM file) could use this flaw to cause the application tocrash. Note: this flaw is not exploitable via the TLS/SSL protocol becausethe data being transferred is not Base64-encoded. (CVE-2015-0292)A denial of service flaw was found in the way OpenSSL handled SSLv2handshake messages. A remote attacker could use this flaw to cause aTLS/SSL server using OpenSSL to exit on a failed assertion if it had boththe SSLv2 protocol and EXPORT-grade cipher suites enabled. (CVE-2015-0293)A use-after-free flaw was found in the way OpenSSL imported malformedElliptic Curve private keys. A specially crafted key file could cause anapplication using OpenSSL to crash when imported. (CVE-2015-0209)An out-of-bounds write flaw was found in the way OpenSSL reused certainASN.1 structures. A remote attacker could possibly use a specially craftedASN.1 structure that, when parsed by an application, would cause thatapplication to crash. (CVE-2015-0287)A NULL pointer dereference flaw was found in OpenSSL's X.509 certificatehandling implementation. A specially crafted X.509 certificate could causean application using OpenSSL to crash if the application attempted toconvert the certificate to a certificate request. (CVE-2015-0288)A NULL pointer dereference was found in the way OpenSSL handled certainPKCS#7 inputs. An attacker able to make an application using OpenSSLverify, decrypt, or parse a specially crafted PKCS#7 input could cause thatapplication to crash. TLS/SSL clients and servers using OpenSSL were notaffected by this flaw. (CVE-2015-0289)Red Hat would like to thank the OpenSSL project for reportingCVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292,and CVE-2015-0293. Upstream acknowledges Stephen Henson of the OpenSSLdevelopment team as the original reporter of CVE-2015-0286, Emilia Käsperof the OpenSSL development team as the original reporter of CVE-2015-0287,Brian Carpenter as the original reporter of CVE-2015-0288, Michal Zalewskiof Google as the original reporter of CVE-2015-0289, Robert Dugal and DavidRamos as the original reporters of CVE-2015-0292, and Sean Burford ofGoogle and Emilia Käsper of the OpenSSL development team as the originalreporters of CVE-2015-0293.All openssl users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. For the update to takeeffect, all services linked to the OpenSSL library must be restarted, orthe system rebooted.

Affected Software

10 affected componentsFixes available
redhat/openssl<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-debuginfo<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-debuginfo<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-devel<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-devel<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-perl<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-static<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-perl<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7
redhat/openssl-static<1.0.1e-30.el6_6.7
1.0.1e-30.el6_6.7

Remediation

Event History

Mar 23, 2015
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2015:0715?

The severity of RHSA-2015:0715 is classified as moderate.

2

How do I fix RHSA-2015:0715?

To fix RHSA-2015:0715, update your OpenSSL packages to version 1.0.1e-30.el6_6.7.

3

What versions of OpenSSL are affected by RHSA-2015:0715?

RHSA-2015:0715 affects OpenSSL versions prior to 1.0.1e-30.el6_6.7.

4

Is there a risk of exploitation from RHSA-2015:0715?

Yes, an invalid pointer use flaw in OpenSSL could potentially lead to remote code execution.

5

What components are impacted by RHSA-2015:0715?

RHSA-2015:0715 impacts OpenSSL, OpenSSL devel, OpenSSL debuginfo, and OpenSSL static packages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203