Description: | Description:
The remote host is missing an update to openssl announced via advisory FEDORA-2007-1444.
The OpenSSL toolkit provides support for secure communications between machines. OpenSSL includes a certificate management tool and shared libraries which provide various cryptographic algorithms and protocols.
ChangeLog:
* Fri Aug 3 2007 Tomas Mraz 0.9.8b-14 - use localhost in testsuite, hopefully fixes slow build in koji - CVE-2007-3108 - fix side channel attack on private keys (#250577) - make ssl session cache id matching strict (#233599) * Wed Jul 25 2007 Tomas Mraz 0.9.8b-13 - allow building on ARM architectures (#245417) - use reference timestamps to prevent multilib conflicts (#218064) - -devel package must require pkgconfig (#241031) References:
[ 1 ] Bug #250574 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=250574 [ 2 ] CVE-2007-3108 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3108 Updated packages:
4ff56d48eaa6017846b5e9e49e540d227aa2eabc openssl-0.9.8b-14.fc7.i686.rpm e59c247885c36084689795e978688b6fd7251e32 openssl-debuginfo-0.9.8b-14.fc7.i686.rpm c0064712d13867bf9b3cc8415c5b1e91d0e497c7 openssl-perl-0.9.8b-14.fc7.ppc64.rpm afeb2c25d37ef291e57ae4837d4932542d4a292b openssl-debuginfo-0.9.8b-14.fc7.ppc64.rpm 086ea64e1b9cfba76ad12d864994665fa387ab26 openssl-0.9.8b-14.fc7.ppc64.rpm 87cb8e3669be8e61b4619e25283df8f868eda20e openssl-devel-0.9.8b-14.fc7.ppc64.rpm dc972280a4e4d077356f1cb7ccf63960439f3d3e openssl-0.9.8b-14.fc7.i386.rpm 620aa50b9459d5e8776aba2af12046119c3191ad openssl-devel-0.9.8b-14.fc7.i386.rpm 0ebf88b026fbd991cb4b62b0e919528e2fcac405 openssl-debuginfo-0.9.8b-14.fc7.i386.rpm f9eff547f71f84dac367beacff988382eabc3a10 openssl-perl-0.9.8b-14.fc7.i386.rpm f5fececbc6600fedeaec7dd429ef815820961d89 openssl-devel-0.9.8b-14.fc7.x86_64.rpm 7e82ed164e5b33d57e5b6077c526a7827a14ee04 openssl-perl-0.9.8b-14.fc7.x86_64.rpm 8a151e49fddf479b8ebd1d5892b248b72032804b openssl-0.9.8b-14.fc7.x86_64.rpm c1058df1c07f5e9a1dc31229df821fcf4c30a0a7 openssl-debuginfo-0.9.8b-14.fc7.x86_64.rpm ccf63970d91d77dcce8fe828e74313f21d883e66 openssl-0.9.8b-14.fc7.ppc.rpm 6432e38cb901cd75023a6ef8c78e88a3f651ffef openssl-perl-0.9.8b-14.fc7.ppc.rpm ceffae71b23eebc5a806dea24c53475524fab242 openssl-devel-0.9.8b-14.fc7.ppc.rpm 03835d76d7fbee4f1c9613ef09ef64c9d8ebda1c openssl-debuginfo-0.9.8b-14.fc7.ppc.rpm 0d6d49b150e21d9666bd2c157def1fe752967609 openssl-0.9.8b-14.fc7.src.rpm
This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://docs.fedoraproject.org/yum/.
Solution: Apply the appropriate updates.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-1444
Risk factor : Low
CVSS Score: 1.2
|