USN-2624-1: OpenSSL update
As a security improvement, this update removes the export cipher suites from the default cipher list to prevent their use in possible downgrade attacks.
Affected Software
Event History
Frequently Asked Questions
What is the purpose of the USN-2624-1 update?
The update removes the export cipher suites from the default cipher list to prevent their use in possible downgrade attacks.
Which versions of libssl1.0.0 are affected by USN-2624-1?
Versions 1.0.1f-1ubuntu11.1, 1.0.1f-1ubuntu9.5, 1.0.1f-1ubuntu2.12, and 1.0.1-4ubuntu5.28 are affected.
How can I fix the vulnerability in libssl1.0.0?
Update libssl1.0.0 to version 1.0.1f-1ubuntu11.1, 1.0.1f-1ubuntu9.5, 1.0.1f-1ubuntu2.12, or 1.0.1-4ubuntu5.28 as per your system's version.
Where can I find more information about USN-2624-1?
You can find more information about USN-2624-1 at the following references: [link1](https://launchpad.net/bugs/1460735), [link2](https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu11.1), [link3](https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu9.5).