First published: Mon Jun 01 2015(Updated: )
As a security improvement, this update removes the export cipher suites from the default cipher list to prevent their use in possible downgrade attacks.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libssl1.0.0 | <1.0.1f-1ubuntu11.1 | 1.0.1f-1ubuntu11.1 |
=15.04 | ||
All of | ||
ubuntu/libssl1.0.0 | <1.0.1f-1ubuntu9.5 | 1.0.1f-1ubuntu9.5 |
=14.10 | ||
All of | ||
ubuntu/libssl1.0.0 | <1.0.1f-1ubuntu2.12 | 1.0.1f-1ubuntu2.12 |
=14.04 | ||
All of | ||
ubuntu/libssl1.0.0 | <1.0.1-4ubuntu5.28 | 1.0.1-4ubuntu5.28 |
=12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The update removes the export cipher suites from the default cipher list to prevent their use in possible downgrade attacks.
Versions 1.0.1f-1ubuntu11.1, 1.0.1f-1ubuntu9.5, 1.0.1f-1ubuntu2.12, and 1.0.1-4ubuntu5.28 are affected.
Update libssl1.0.0 to version 1.0.1f-1ubuntu11.1, 1.0.1f-1ubuntu9.5, 1.0.1f-1ubuntu2.12, or 1.0.1-4ubuntu5.28 as per your system's version.
You can find more information about USN-2624-1 at the following references: [link1](https://launchpad.net/bugs/1460735), [link2](https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu11.1), [link3](https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu9.5).