TSLSA-2003-0005 - openssl

From: Trustix Secure Linux Advisor (tslat_private)
Date: Fri Feb 21 2003 - 07:31:08 PST

  • Next message: Oriol Carreas: "RE: PHPNuke SQL Injection"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Trustix Secure Linux Security Advisory #2003-0005
    
    Package name:      openssl
    Summary:           Security fix
    Date:              2003-02-20
    Affected versions: TSL 1.1, 1.2, 1.5
    
    - --------------------------------------------------------------------------
    Package description:
      A C library that provides various crytographic algorithms and protocols,
      including DES, RC4, RSA, and SSL. Includes shared libraries.
      
    
    Problem description:
      From the openssl advisory:
      OpenSSL version since 0.9.6c supposedly treat block cipher padding
      errors like MAC verification errors during record decryption
      (see http://www.openssl.org/~bodo/tls-cbc.txt), but MAC verification
      was still skipped after detection of a padding error, which allowed
      the timing attack.  (Note that it is likely that other SSL/TLS
      implementations will have similar problems.)
    
      OpenSSL 0.9.6i and 0.9.7a perform a MAC computation even if incorrrect
      block cipher padding has been found to minimize information leaked via
      timing.  For earlier versions starting with 0.9.6e, the enclosed
      security patch can be used.
    
    
    Action:
      We recommend that all systems with this package installed be upgraded.
    
    
    Location:
      All TSL updates are available from
      <URI:http://www.trustix.net/pub/Trustix/updates/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>
    
    
    About Trustix Secure Linux:
      Trustix Secure Linux is a small Linux distribution for servers. With focus
      on security and stability, the system is painlessly kept safe and up to
      date from day one using swup, the automated software updater.
    
    
    Automatic updates:
      Users of the SWUP tool can enjoy having updates automatically
      installed using 'swup --upgrade'.
    
      Get SWUP from:
      <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>
    
    
    Public testing:
      These packages have been available for public testing for some time.
      If you want to contribute by testing the various packages in the
      testing tree, please feel free to share your findings on the
      tsl-discuss mailinglist.
      The testing tree is located at
      <URI:http://www.trustix.net/pub/Trustix/testing/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/testing/>
      
    
    Questions?
      Check out our mailing lists:
      <URI:http://www.trustix.net/support/>
    
    
    Verification:
      This advisory along with all TSL packages are signed with the TSL sign key.
      This key is available from:
      <URI:http://www.trustix.net/TSL-GPG-KEY>
    
      The advisory itself is available from the errata pages at
      <URI:http://www.trustix.net/errata/trustix-1.2/> and
      <URI:http://www.trustix.net/errata/trustix-1.5/>
      or directly at
      <URI:http://www.trustix.net/errata/misc/2003/TSL-2003-0005-openssl.asc.txt>
    
    
    MD5sums of the packages:
    - --------------------------------------------------------------------------
    641cc1ec2c74ba8cb398495b71343c17  ./1.5/SRPMS/openssl-0.9.6-12tr.src.rpm
    e1847c407ff203d8fa9a92edceb0ec3f  ./1.5/RPMS/openssl-support-0.9.6-12tr.i586.rpm
    3e8330fbeca0065f7110f3617b49d4cb  ./1.5/RPMS/openssl-python-0.9.6-12tr.i586.rpm
    d6f750a842a25696844bdac0fdd3088d  ./1.5/RPMS/openssl-devel-0.9.6-12tr.i586.rpm
    e02fabb3aeefa3bcacb6722348d73bf3  ./1.5/RPMS/openssl-0.9.6-12tr.i586.rpm
    641cc1ec2c74ba8cb398495b71343c17  ./1.2/SRPMS/openssl-0.9.6-12tr.src.rpm
    e51a2ebce95d3cf48996f3329b6afcf9  ./1.2/RPMS/openssl-support-0.9.6-12tr.i586.rpm
    ccb26bafabae3ad619d8d2ff4d76b8c6  ./1.2/RPMS/openssl-python-0.9.6-12tr.i586.rpm
    0003d4d1f1227a9afebcfe88eec8f59f  ./1.2/RPMS/openssl-devel-0.9.6-12tr.i586.rpm
    d4283b1a16b1d7b134f05d9b94f390f8  ./1.2/RPMS/openssl-0.9.6-12tr.i586.rpm
    641cc1ec2c74ba8cb398495b71343c17  ./1.1/SRPMS/openssl-0.9.6-12tr.src.rpm
    973703fdbf2193af26d488f5c9c13046  ./1.1/RPMS/openssl-support-0.9.6-12tr.i586.rpm
    5d2688fa3e10cd651e382b5995b37f0b  ./1.1/RPMS/openssl-python-0.9.6-12tr.i586.rpm
    efdc6af94f7c9a3d5e4250995743fcea  ./1.1/RPMS/openssl-devel-0.9.6-12tr.i586.rpm
    e18b06c12d94fd5d9bb4b900a4135185  ./1.1/RPMS/openssl-0.9.6-12tr.i586.rpm
    - --------------------------------------------------------------------------
    
    
    Trustix Security Team
    
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org
    
    iD8DBQE+Vi5hwRTcg4BxxS0RAhcEAJ9mAeDfTR+814PVDuVq2ODK5yo3OACff97I
    Yka8IMnXybdWy6fpq34Ma8s=
    =gaZl
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Fri Feb 21 2003 - 14:52:40 PST