RHSA-2019:0483: Moderate: openssl security and bug fix update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.<br>Security Fix(es):<br><li> openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Perform the RSA signature self-tests with SHA-256 (BZ#1673914)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:0483?
The severity of RHSA-2019:0483 is classified as important due to the side-channel vulnerabilities it addresses.
How do I fix RHSA-2019:0483?
To fix RHSA-2019:0483, update the OpenSSL package to version 1.0.2k-16.el7_6.1 or later.
What does RHSA-2019:0483 address?
RHSA-2019:0483 addresses a side-channel vulnerability on SMT/Hyper-Threading architectures in OpenSSL.
Which versions of OpenSSL are affected by RHSA-2019:0483?
Versions of OpenSSL prior to 1.0.2k-16.el7_6.1 are affected by RHSA-2019:0483.
Is there a specific package I need to update for RHSA-2019:0483?
Yes, you need to update the openssl, openssl-libs, openssl-devel, and related packages to version 1.0.2k-16.el7_6.1 or later.