drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Verwendung schwacher Verschlüsselung in OpenSSL
Name: |
Verwendung schwacher Verschlüsselung in OpenSSL |
|
ID: |
USN-2863-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 LTS |
|
Datum: |
Do, 7. Januar 2016, 21:58 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7575 |
|
Applikationen: |
OpenSSL |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============6025914341272019701== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="kbCWj72wFStWFi696GxePTc2lR5dK8Bir"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --kbCWj72wFStWFi696GxePTc2lR5dK8Bir Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-2863-1 January 07, 2016
openssl vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
OpenSSL could be made to expose sensitive information over the network.
Software Description: - openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
Karthikeyan Bhargavan and Gaetan Leurent discovered that OpenSSL incorrectly allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 LTS: libssl1.0.0 1.0.1-4ubuntu5.33
After a standard system update you need to reboot your computer to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-2863-1 CVE-2015-7575
Package Information: https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.33
--kbCWj72wFStWFi696GxePTc2lR5dK8Bir Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAEBCgAGBQJWjr/5AAoJEGVp2FWnRL6Tb1gP/3/gFRbuG9gmHT9YWLfy3Kha 1c0ToMzhFZ7lqg4DNC+33/1WgleHwT3q/dTR6W9nFveXYvYEFai8dvWG/h+lg86N GG693DrLrC8YXgM9gkjUuyRWWl7tVDEbLSjsKH6GZBJ/uPJz+EJ/TKKPf4ntq3G9 lqAthsGDjtj0ma9hYvfCA/N/YebQ9aGIzUJlAu32xAIIX/Xq2Z9cUm2BCpRDrLVN 4FcOc4dSo/c4L2op0jhsC3EfPKgEva9MP9dxcDikxsqxTUNN63KB/thM64PehKOR o2o7FEWXNL04msySvkfREf8iOl1TzB0p6Eqgm7aIpi8O1N/s2eWaUcd7zlWazmIO PUDq4o6RlsoTpmuF8x4ohiRgExIYzidtustafsdDJWou2Dd67Z5sgECq+hz7L6ni mp3IenwK9lWJB3SQOwGwXMeC0FlAsWxJLpDBguSWfM33PeZeXEfPFB2WBmUfE+/F Je4myTUO4tATH8HG1+OxyOB29Y+Vh49ZHGStxyZkGTAYIDcV6EfKCmmqWBK8WH57 rfyTYyJL2DNcOvHqfFiKOPF7qsIjgm8b35Z0fdWgwxLIyhbNP2HoELS6WMk9a6da QFwqIjhbiTsKPs499WNVXcLlHvnQCYoFD8jzio/jz24GWQJdsEU4j92TKD48xiWY ZPs1g0oyzv5ojWt6D/Iw =OqSf -----END PGP SIGNATURE-----
--kbCWj72wFStWFi696GxePTc2lR5dK8Bir--
--===============6025914341272019701== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============6025914341272019701==--
|
|
|
|