Description: | Description:
The remote host is missing an update to openssl announced via advisory FEDORA-2008-4723.
Update Information:
Fixes moderate impact security issue CVE-2008-0891 and low impact security issue CVE-2008-1672. See also http://www.openssl.org/news/secadv_20080528.txt All applications and system services which utilize OpenSSL library must be restarted for the updates to take effect. ChangeLog:
* Wed May 28 2008 Tomas Mraz 0.9.8g-9 - fix CVE-2008-0891 - server name extension crash (#448492) - fix CVE-2008-1672 - server key exchange message omit crash (#448495) * Tue May 27 2008 Tomas Mraz 0.9.8g-8 - super-H arch support - drop workaround for bug 199604 as it should be fixed in gcc-4.3 * Mon May 19 2008 Tom spot Callaway 0.9.8g-7 - sparc handling
References:
[ 1 ] Bug #448492 - CVE-2008-0891 openssl: Server Name extension crash https://bugzilla.redhat.com/show_bug.cgi?id=448492 [ 2 ] Bug #448495 - CVE-2008-1672 openssl: Omit Server Key Exchange message crash https://bugzilla.redhat.com/show_bug.cgi?id=448495
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update openssl' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-4723
Risk factor : Medium
CVSS Score: 4.3
|