[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2018:3221-01 -- Redhat openssl

ID: oval:org.secpod.oval:def:502382Date: (C)2020-11-05   (M)2024-04-17
Class: PATCHFamily: unix




OpenSSL is a toolkit that implements the Secure Sockets Layer and Transport Layer Security protocols, as well as a full-strength general-purpose cryptography library. Security Fix: * openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries * openssl: Malicious server can send large prime to client during DH TLS handshake causing the client to hang * openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service * openssl: Malformed X.509 IPAdressFamily could cause OOB read * openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 7
Product:
openssl
Reference:
RHSA-2018:3221-01
CVE-2017-3735
CVE-2018-0495
CVE-2018-0732
CVE-2018-0737
CVE-2018-0739
CVE    5
CVE-2018-0495
CVE-2018-0737
CVE-2018-0739
CVE-2017-3735
...

© SecPod Technologies