Descripción: | Description:
The remote host is missing updates announced in advisory CLA-2004:834.
OpenSSL[1] implements the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as full-strength general purpose cryptography functions. It's used (as a library) by several projects, like Apache, OpenSSH, Bind, OpenLDAP and many others clients and servers programs.
This update fixes three denial of service vulnerabilities that affect OpenSSL versions distributed with Conectiva Linux:
CVE-2004-0079: Null-pointer assignment during SSL handshake[3]. A remote attacker can exploit this vulnerability by performing a specially crafted SSL handshake that will crash the application. This vulnerability was discovered by the OpenSSL team using the Codenomicon TLS Test Tool and affects OpenSSL versions distributed with Conectiva Linux 8 (0.9.6c) and 9 (0.9.7a).
CVE-2004-0081: Infinite loop when handling unknown TLS message types[4]. A remote attacker can exploit this vulnerability by sending specially crafted TLS messages, causing the application to enter an infinite loop. Conectiva Linux 9 (OpenSSL-0.9.7a) is not vulnerable to this issue.
CVE-2004-0112: Out-of-bounds read with Kerberos ciphersuites[5]. Stephen Henson discovered a vulnerability in the SSL/TLS handshaking code when using Kerberos ciphersuites. A remote attacker can exploit it to crash an application which uses Kerberos ciphersuites. The OpenSSL version distributed with Conectiva Linux 8 (OpenSSL-0.9.6c) is not vulnerable to this issue and there are no known applications using Kerberos ciphersuites in Conectiva Linux 9.
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'
http://www.openssl.org/ http://www.openssl.org/news/secadv_20040317.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0079 http://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0081 http://cve.mitre.org/cgi-bin/cvename.cgi?name=2004-0112 http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:834 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004
Risk factor : Medium
CVSS Score: 5.0
|