RHSA-2016:1137: Important: openssl security update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) andTransport Layer Security (TLS) protocols, as well as a full-strengthgeneral-purpose cryptography library.Security Fix(es): A flaw was found in the way OpenSSL encoded certain ASN.1 data structures. An attacker could use this flaw to create a specially crafted certificate which,when verified or re-encoded by OpenSSL, could cause it to crash, or executearbitrary code using the permissions of the user running an application compiledagainst the OpenSSL library. (CVE-2016-2108)Red Hat would like to thank the OpenSSL project for reporting this issue.Upstream acknowledges Huzaifa Sidhpurwala (Red Hat), Hanno Bock, and DavidBenjamin (Google) as the original reporters.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:1137?
The severity of RHSA-2016:1137 is classified as important.
How do I fix RHSA-2016:1137?
To fix RHSA-2016:1137, you should update the affected OpenSSL packages to the latest version provided by Red Hat.
Which versions of OpenSSL are affected by RHSA-2016:1137?
OpenSSL version 0.9.8e-40.el5_11 is affected by RHSA-2016:1137.
Is OpenSSL version 0.9.8e-40.el5_11 secure?
No, OpenSSL version 0.9.8e-40.el5_11 is not secure due to vulnerabilities addressed in RHSA-2016:1137.
What types of packages are affected by RHSA-2016:1137?
The affected packages include openssl, openssl-debuginfo, openssl-devel, and openssl-perl.