Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59680
Category:Turbolinux Local Security Tests
Title:Turbolinux TLSA-2007-52 (openssl)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to openssl
announced via advisory TLSA-2007-52.

The OpenSSL Project is a collaborative effort to develop a robust,
commercial-grade, full-featured Open Source toolkit implementing the
Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1)
protocols as well as a full-strength general purpose cryptography library.

Multiple vulnerabilities exist in openssl.

Buffer overflow openssl.
Allows remote attackers to force a client and server to use a weaker protocol.
Allow local users to conduct a side-channel attack and retrieve RSA private keys.
Allow remote attackers to execute arbitrary code via a crafted packet that
triggers a one-byte buffer underflow.
Remote attackers to execute arbitrary code via unspecified vectors.

Solution: Please use the turbopkg (zabom) tool to apply the update.
http://www.securityspace.com/smysecure/catid.html?in=TLSA-2007-52

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-3738
1016943
http://securitytracker.com/id?1016943
1017522
http://securitytracker.com/id?1017522
102668
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1
102711
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102711-1
2006-0054
http://www.trustix.org/errata/2006/0054
20060928 [SECURITY] OpenSSL 0.9.8d and 0.9.7l released
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049715.html
20060928 rPSA-2006-0175-1 openssl openssl-scripts
http://www.securityfocus.com/archive/1/447318/100/0/threaded
20060929 rPSA-2006-0175-2 openssl openssl-scripts
http://www.securityfocus.com/archive/1/447393/100/0/threaded
20061001-01-P
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
20061108 Multiple Vulnerabilities in OpenSSL Library
http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html
20061108 Multiple Vulnerabilities in OpenSSL library
http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml
20070110 VMware ESX server security updates
http://www.securityfocus.com/archive/1/456546/100/200/threaded
20070602 Recent OpenSSL exploits
http://www.securityfocus.com/archive/1/470460/100/0/threaded
201531
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201531-1
20249
http://www.securityfocus.com/bid/20249
22083
http://www.securityfocus.com/bid/22083
22094
http://secunia.com/advisories/22094
22116
http://secunia.com/advisories/22116
22130
http://secunia.com/advisories/22130
22165
http://secunia.com/advisories/22165
22166
http://secunia.com/advisories/22166
22172
http://secunia.com/advisories/22172
22186
http://secunia.com/advisories/22186
22193
http://secunia.com/advisories/22193
22207
http://secunia.com/advisories/22207
22212
http://secunia.com/advisories/22212
22216
http://secunia.com/advisories/22216
22220
http://secunia.com/advisories/22220
22240
http://secunia.com/advisories/22240
22259
http://secunia.com/advisories/22259
22260
http://secunia.com/advisories/22260
22284
http://secunia.com/advisories/22284
22298
http://secunia.com/advisories/22298
22330
http://secunia.com/advisories/22330
22385
http://secunia.com/advisories/22385
22460
http://secunia.com/advisories/22460
22487
http://secunia.com/advisories/22487
22500
http://secunia.com/advisories/22500
22544
http://secunia.com/advisories/22544
22626
http://secunia.com/advisories/22626
22633
http://secunia.com/advisories/22633
22654
http://secunia.com/advisories/22654
22758
http://secunia.com/advisories/22758
22772
http://secunia.com/advisories/22772
22791
http://secunia.com/advisories/22791
22799
http://secunia.com/advisories/22799
23038
http://secunia.com/advisories/23038
23155
http://secunia.com/advisories/23155
23280
http://secunia.com/advisories/23280
23309
http://secunia.com/advisories/23309
23340
http://secunia.com/advisories/23340
23680
http://secunia.com/advisories/23680
23794
http://secunia.com/advisories/23794
23915
http://secunia.com/advisories/23915
24930
http://secunia.com/advisories/24930
24950
http://secunia.com/advisories/24950
25889
http://secunia.com/advisories/25889
26329
http://secunia.com/advisories/26329
29262
http://www.osvdb.org/29262
30124
http://secunia.com/advisories/30124
30161
http://secunia.com/advisories/30161
31492
http://secunia.com/advisories/31492
ADV-2006-3820
http://www.vupen.com/english/advisories/2006/3820
ADV-2006-3860
http://www.vupen.com/english/advisories/2006/3860
ADV-2006-3869
http://www.vupen.com/english/advisories/2006/3869
ADV-2006-3902
http://www.vupen.com/english/advisories/2006/3902
ADV-2006-3936
http://www.vupen.com/english/advisories/2006/3936
ADV-2006-4036
http://www.vupen.com/english/advisories/2006/4036
ADV-2006-4264
http://www.vupen.com/english/advisories/2006/4264
ADV-2006-4314
http://www.vupen.com/english/advisories/2006/4314
ADV-2006-4401
http://www.vupen.com/english/advisories/2006/4401
ADV-2006-4417
http://www.vupen.com/english/advisories/2006/4417
ADV-2006-4443
http://www.vupen.com/english/advisories/2006/4443
ADV-2006-4750
http://www.vupen.com/english/advisories/2006/4750
ADV-2007-0343
http://www.vupen.com/english/advisories/2007/0343
ADV-2007-1401
http://www.vupen.com/english/advisories/2007/1401
ADV-2007-2315
http://www.vupen.com/english/advisories/2007/2315
ADV-2007-2783
http://www.vupen.com/english/advisories/2007/2783
APPLE-SA-2006-11-28
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
DSA-1185
http://www.debian.org/security/2006/dsa-1185
DSA-1195
http://www.debian.org/security/2006/dsa-1195
FreeBSD-SA-06:23
http://security.freebsd.org/advisories/FreeBSD-SA-06:23.openssl.asc
GLSA-200610-11
http://security.gentoo.org/glsa/glsa-200610-11.xml
GLSA-200612-11
http://www.gentoo.org/security/en/glsa/glsa-200612-11.xml
GLSA-200805-07
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml
HPSBMA02250
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771
HPSBOV02683
http://marc.info/?l=bugtraq&m=130497311408250&w=2
HPSBTU02207
https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144
HPSBUX02174
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00805100
HPSBUX02186
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540
MDKSA-2006:172
http://www.mandriva.com/security/advisories?name=MDKSA-2006:172
MDKSA-2006:177
http://www.mandriva.com/security/advisories?name=MDKSA-2006:177
MDKSA-2006:178
http://www.mandriva.com/security/advisories?name=MDKSA-2006:178
NetBSD-SA2008-007
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc
OpenPKG-SA-2006.021
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.021-openssl.html
RHSA-2006:0695
http://www.redhat.com/support/errata/RHSA-2006-0695.html
RHSA-2008:0629
http://www.redhat.com/support/errata/RHSA-2008-0629.html
SSA:2006-272-01
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.676946
SSRT061213
SSRT061239
SSRT061275
SSRT071299
SSRT071304
SSRT090208
SUSE-SA:2006:058
http://www.novell.com/linux/security/advisories/2006_58_openssl.html
SUSE-SR:2006:024
http://www.novell.com/linux/security/advisories/2006_24_sr.html
TA06-333A
http://www.us-cert.gov/cas/techalerts/TA06-333A.html
USN-353-1
http://www.ubuntu.com/usn/usn-353-1
VU#547300
http://www.kb.cert.org/vuls/id/547300
[3.9] 20061007 013: SECURITY FIX: October 7, 2006
http://openbsd.org/errata.html#openssl2
http://docs.info.apple.com/article.html?artnum=304829
http://issues.rpath.com/browse/RPL-613
http://kolab.org/security/kolab-vendor-notice-11.txt
http://openvpn.net/changelog.html
http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227
http://support.avaya.com/elmodocs2/security/ASA-2006-220.htm
http://support.avaya.com/elmodocs2/security/ASA-2006-260.htm
http://www.openssl.org/news/secadv_20060928.txt
http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
http://www.serv-u.com/releasenotes/
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
http://www.xerox.com/downloads/usa/en/c/cert_ESSNetwork_XRX07001_v1.pdf
http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=498093&RenditionID=&poid=8881
openssl-sslgetsharedciphers-bo(29237)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29237
oval:org.mitre.oval:def:4256
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4256
oval:org.mitre.oval:def:9370
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9370
Common Vulnerability Exposure (CVE) ID: CVE-2007-3108
20070813 FLEA-2007-0043-1 openssl
http://www.securityfocus.com/archive/1/476341/100/0/threaded
20080108 VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages
http://www.securityfocus.com/archive/1/485936/100/0/threaded
20080123 UPDATED VMSA-2008-0001.1 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages
http://www.securityfocus.com/archive/1/486859/100/0/threaded
25163
http://www.securityfocus.com/bid/25163
26411
http://secunia.com/advisories/26411
26893
http://secunia.com/advisories/26893
27021
http://secunia.com/advisories/27021
27078
http://secunia.com/advisories/27078
27097
http://secunia.com/advisories/27097
27205
http://secunia.com/advisories/27205
27330
http://secunia.com/advisories/27330
27770
http://secunia.com/advisories/27770
27870
http://secunia.com/advisories/27870
28368
http://secunia.com/advisories/28368
30220
http://secunia.com/advisories/30220
31467
http://secunia.com/advisories/31467
31489
http://secunia.com/advisories/31489
31531
http://secunia.com/advisories/31531
ADV-2007-2759
http://www.vupen.com/english/advisories/2007/2759
ADV-2007-4010
http://www.vupen.com/english/advisories/2007/4010
ADV-2008-0064
http://www.vupen.com/english/advisories/2008/0064
ADV-2008-2361
http://www.vupen.com/english/advisories/2008/2361
ADV-2008-2362
http://www.vupen.com/english/advisories/2008/2362
ADV-2008-2396
http://www.vupen.com/english/advisories/2008/2396
DSA-1571
http://www.debian.org/security/2008/dsa-1571
GLSA-200710-06
http://security.gentoo.org/glsa/glsa-200710-06.xml
MDKSA-2007:193
http://www.mandriva.com/security/advisories?name=MDKSA-2007:193
RHSA-2007:0813
http://www.redhat.com/support/errata/RHSA-2007-0813.html
RHSA-2007:0964
http://www.redhat.com/support/errata/RHSA-2007-0964.html
RHSA-2007:1003
http://www.redhat.com/support/errata/RHSA-2007-1003.html
USN-522-1
https://usn.ubuntu.com/522-1/
VU#724968
http://www.kb.cert.org/vuls/id/724968
[Security-announce] 20080107 VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages
http://lists.vmware.com/pipermail/security-announce/2008/000002.html
http://cvs.openssl.org/chngview?cn=16275
http://openssl.org/news/patch-CVE-2007-3108.txt
http://support.attachmate.com/techdocs/2374.html
http://support.avaya.com/elmodocs2/security/ASA-2007-485.htm
http://www.bluecoat.com/support/securityadvisories/advisory_openssl_rsa_key_reconstruction_vulnerability
http://www.kb.cert.org/vuls/id/RGII-74KLP3
http://www.vmware.com/security/advisories/VMSA-2008-0001.html
http://www.vmware.com/security/advisories/VMSA-2008-0013.html
https://issues.rpath.com/browse/RPL-1613
https://issues.rpath.com/browse/RPL-1633
oval:org.mitre.oval:def:9984
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9984
Common Vulnerability Exposure (CVE) ID: CVE-2007-4995
1018810
http://securitytracker.com/id?1018810
20071012 OpenSSL Security Advisory
http://www.securityfocus.com/archive/1/482167/100/0/threaded
25878
http://secunia.com/advisories/25878
26055
http://www.securityfocus.com/bid/26055
27217
http://secunia.com/advisories/27217
27271
http://secunia.com/advisories/27271
27363
http://secunia.com/advisories/27363
27434
http://secunia.com/advisories/27434
27933
http://secunia.com/advisories/27933
28084
http://secunia.com/advisories/28084
30852
http://secunia.com/advisories/30852
ADV-2007-3487
http://www.vupen.com/english/advisories/2007/3487
ADV-2007-4219
http://www.vupen.com/english/advisories/2007/4219
ADV-2008-1937
http://www.vupen.com/english/advisories/2008/1937/references
FEDORA-2007-725
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00218.html
GLSA-200710-30
http://security.gentoo.org/glsa/glsa-200710-30.xml
HPSBUX02296
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01299773
MDKSA-2007:237
http://www.mandriva.com/security/advisories?name=MDKSA-2007:237
SSRT071504
SUSE-SR:2007:021
http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html
USN-534-1
https://usn.ubuntu.com/534-1/
http://bugs.gentoo.org/show_bug.cgi?id=195634
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738962
http://www.openssl.org/news/secadv_20071012.txt
openssl-dtls-code-execution(37185)
https://exchange.xforce.ibmcloud.com/vulnerabilities/37185
oval:org.mitre.oval:def:10288
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10288
Common Vulnerability Exposure (CVE) ID: CVE-2007-5135
http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
BugTraq ID: 25831
http://www.securityfocus.com/bid/25831
Bugtraq: 20070927 OpenSSL SSL_get_shared_ciphers() off-by-one buffer overflow (Google Search)
http://www.securityfocus.com/archive/1/480855/100/0/threaded
Bugtraq: 20071004 Re: OpenSSL SSL_get_shared_ciphers() off-by-one buffer overflow (Google Search)
http://www.securityfocus.com/archive/1/481217/100/0/threaded
Bugtraq: 20071003 FLEA-2007-0058-1 openssl openssl-scripts (Google Search)
http://www.securityfocus.com/archive/1/481488/100/0/threaded
http://www.securityfocus.com/archive/1/481506/100/0/threaded
Bugtraq: 20080108 VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages (Google Search)
Bugtraq: 20080123 UPDATED VMSA-2008-0001.1 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages (Google Search)
Debian Security Information: DSA-1379 (Google Search)
http://www.debian.org/security/2007/dsa-1379
FreeBSD Security Advisory: FreeBSD-SA-07:08
http://security.freebsd.org/advisories/FreeBSD-SA-07:08.openssl.asc
HPdes Security Advisory: HPSBUX02292
http://www.securityfocus.com/archive/1/484353/100/0/threaded
HPdes Security Advisory: SSRT071499
https://bugs.gentoo.org/show_bug.cgi?id=194039
NETBSD Security Advisory: NetBSD-SA2008-007
OpenBSD Security Advisory: [4.0] 017: SECURITY FIX: October 10, 2007
http://www.openbsd.org/errata40.html
OpenBSD Security Advisory: [4.1] 011: SECURITY FIX: October 10, 2007
http://www.openbsd.org/errata41.html
OpenBSD Security Advisory: [4.2] 002: SECURITY FIX: October 10, 2007
http://www.openbsd.org/errata42.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10904
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5337
http://www.securitytracker.com/id?1018755
http://secunia.com/advisories/27012
http://secunia.com/advisories/27031
http://secunia.com/advisories/27051
http://secunia.com/advisories/27186
http://secunia.com/advisories/27229
http://secunia.com/advisories/27394
http://secunia.com/advisories/27851
http://secunia.com/advisories/27961
http://secunia.com/advisories/29242
http://secunia.com/advisories/31308
http://secunia.com/advisories/31326
http://securityreason.com/securityalert/3179
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103130-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200858-1
SuSE Security Announcement: SUSE-SR:2007:020 (Google Search)
http://www.novell.com/linux/security/advisories/2007_20_sr.html
SuSE Security Announcement: SUSE-SR:2008:005 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
http://www.vupen.com/english/advisories/2007/3325
http://www.vupen.com/english/advisories/2007/3625
http://www.vupen.com/english/advisories/2007/4042
http://www.vupen.com/english/advisories/2007/4144
http://www.vupen.com/english/advisories/2008/2268
XForce ISS Database: openssl-sslgetshared-bo(36837)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36837
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.