RHSA-2015:0752: Moderate: openssl security update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)and Transport Layer Security (TLS v1) protocols, as well as afull-strength, general purpose cryptography library.An invalid pointer use flaw was found in OpenSSL's ASN1TYPEcmp()function. A remote attacker could crash a TLS/SSL client or server usingOpenSSL via a specially crafted X.509 certificate when theattacker-supplied certificate was verified by the application.(CVE-2015-0286)An integer underflow flaw, leading to a buffer overflow, was found in theway OpenSSL decoded malformed Base64-encoded inputs. An attacker able tomake an application using OpenSSL decode a specially crafted Base64-encodedinput (such as a PEM file) could use this flaw to cause the application tocrash. Note: this flaw is not exploitable via the TLS/SSL protocol becausethe data being transferred is not Base64-encoded. (CVE-2015-0292)A denial of service flaw was found in the way OpenSSL handled SSLv2handshake messages. A remote attacker could use this flaw to cause aTLS/SSL server using OpenSSL to exit on a failed assertion if it had boththe SSLv2 protocol and EXPORT-grade cipher suites enabled. (CVE-2015-0293)A use-after-free flaw was found in the way OpenSSL imported malformedElliptic Curve private keys. A specially crafted key file could cause anapplication using OpenSSL to crash when imported. (CVE-2015-0209)An out-of-bounds write flaw was found in the way OpenSSL reused certainASN.1 structures. A remote attacker could possibly use a specially craftedASN.1 structure that, when parsed by an application, would cause thatapplication to crash. (CVE-2015-0287)A NULL pointer dereference flaw was found in OpenSSL's X.509 certificatehandling implementation. A specially crafted X.509 certificate could causean application using OpenSSL to crash if the application attempted toconvert the certificate to a certificate request. (CVE-2015-0288)A NULL pointer dereference was found in the way OpenSSL handled certainPKCS#7 inputs. An attacker able to make an application using OpenSSLverify, decrypt, or parse a specially crafted PKCS#7 input could cause thatapplication to crash. TLS/SSL clients and servers using OpenSSL were notaffected by this flaw. (CVE-2015-0289)Red Hat would like to thank the OpenSSL project for reportingCVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292,and CVE-2015-0293. Upstream acknowledges Stephen Henson of the OpenSSLdevelopment team as the original reporter of CVE-2015-0286, Emilia Käsperof the OpenSSL development team as the original reporter of CVE-2015-0287,Brian Carpenter as the original reporter of CVE-2015-0288, Michal Zalewskiof Google as the original reporter of CVE-2015-0289, Robert Dugal and DavidRamos as the original reporters of CVE-2015-0292, and Sean Burford ofGoogle and Emilia Käsper of the OpenSSL development team as the originalreporters of CVE-2015-0293.All openssl users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. For the update to takeeffect, all services linked to the OpenSSL library must be restarted, orthe system rebooted.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2015:0752?
RHSA-2015:0752 has a moderate severity rating due to the identified invalid pointer use flaw.
How do I fix RHSA-2015:0752?
To fix RHSA-2015:0752, update the OpenSSL package to version 1.0.1e-30.el6_6.7 or later.
What systems are affected by RHSA-2015:0752?
RHSA-2015:0752 affects Red Hat's OpenSSL packages on systems running versions prior to 1.0.1e-30.el6_6.7.
Is there a workaround for RHSA-2015:0752?
There are no documented workarounds for RHSA-2015:0752; applying the appropriate update is recommended.
What specific OpenSSL components does RHSA-2015:0752 impact?
RHSA-2015:0752 impacts several OpenSSL components, including openssl, openssl-debuginfo, and openssl-devel.