USN-3628-2: OpenSSL vulnerability

19 April 2018

openssl vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

Summary

OpenSSL could allow access to sensitve information.

Software Description

  • openssl - Secure Socket Layer (SSL) cryptographic library and tools

Details

USN-3628-1 fixed a vulnerability in OpenSSL. This update provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA key generation. An attacker could possibly use this issue to perform a cache-timing attack and recover private RSA keys.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 12.04 ESM
libssl1.0.0 - 1.0.1-4ubuntu5.41

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make all the necessary changes.

References



from Ubuntu Security Notices https://ift.tt/2HCowVI