USN-3181-1: OpenSSL vulnerabilities
Guido Vranken discovered that OpenSSL used undefined behaviour when performing pointer arithmetic. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS as other releases were fixed in a previous security update. (CVE-2016-2177) It was discovered that OpenSSL did not properly handle Montgomery multiplication, resulting in incorrect results leading to transient failures. This issue only applied to Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7055) It was discovered that OpenSSL did not properly use constant-time operations when performing ECDSA P-256 signing. A remote attacker could possibly use this issue to perform a timing attack and recover private ECDSA keys. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2016-7056) Shi Lei discovered that OpenSSL incorrectly handled certain warning alerts. A remote attacker could possibly use this issue to cause OpenSSL to stop responding, resulting in a denial of service. (CVE-2016-8610) Robert Święcki discovered that OpenSSL incorrectly handled certain truncated packets. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2017-3731) It was discovered that OpenSSL incorrectly performed the x8664 Montgomery squaring procedure. While unlikely, a remote attacker could possibly use this issue to recover private keys. This issue only applied to Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2017-3732)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability severity of USN-3181-1?
The severity of USN-3181-1 is rated as potentially critical due to the possibility of denial of service resulting from the undefined behavior in OpenSSL.
How do I resolve the issues outlined in USN-3181-1?
To fix the vulnerabilities in USN-3181-1, users should upgrade to a patched version of the libssl1.0.0 package according to their Ubuntu version.
Which Ubuntu versions are affected by the vulnerability USN-3181-1?
USN-3181-1 specifically affects Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.
What can a remote attacker do by exploiting USN-3181-1?
A remote attacker can potentially crash OpenSSL, leading to a denial of service for affected systems.
What packages need updates due to USN-3181-1?
The libssl1.0.0 package in various versions requires updating to prevent exploitation related to USN-3181-1.