[Oraclevm-errata] OVMSA-2014-0008 Important: Oracle VM 3.2 onpenssl security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Wed Jun 18 10:15:25 PDT 2014


Oracle VM Security Advisory OVMSA-2014-0008

The following updated rpms for Oracle VM 3.2 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
openssl-0.9.8e-27.el5_10.3.x86_64.rpm


SRPMS:
http://oss.oracle.com/oraclevm/server/3.2/SRPMS-updates/openssl-0.9.8e-27.el5_10.3.src.rpm



Description of changes:

[0.9.8e-27.3]
- fix for CVE-2014-0224 - SSL/TLS MITM vulnerability

[0.9.8e-27.1]
- replace expired GlobalSign Root CA certificate in ca-bundle.crt

[0.9.8e-27]
- fix for CVE-2013-0169 - SSL/TLS CBC timing attack (#907589)
- fix for CVE-2013-0166 - DoS in OCSP signatures checking (#908052)
- enable compression only if explicitly asked for or OPENSSL_DEFAULT_ZLIB
   environment variable is set (fixes CVE-2012-4929 #857051)
- use __secure_getenv() everywhere instead of getenv() (#839735)

[0.9.8e-26]
- fix for CVE-2012-2333 - improper checking for record length in DTLS 
(#820686)

[0.9.8e-25]
- fix for CVE-2012-2110 - memory corruption in asn1_d2i_read_bio() (#814185)

[0.9.8e-23]
- fix problem with the SGC restart patch that might terminate handshake
   incorrectly
- fix for CVE-2012-0884 - MMA weakness in CMS and PKCS#7 code (#802725)
- fix for CVE-2012-1165 - NULL read dereference on bad MIME headers 
(#802489)

[0.9.8e-22]
- fix for CVE-2011-4108 & CVE-2012-0050 - DTLS plaintext recovery
   vulnerability and additional DTLS fixes (#771770)
- fix for CVE-2011-4109 - double free in policy checks (#771771)
- fix for CVE-2011-4576 - uninitialized SSL 3.0 padding (#771775)
- fix for CVE-2011-4619 - SGC restart DoS attack (#771780)

[0.9.8e-21]
- add known answer test for SHA2 algorithms (#740866)
- make default private key length in certificate Makefile 2048 bits
   (can be changed with PRIVATE_KEY_BITS setting) (#745410)
- fix incorrect return value in parse_yesno() (#726593)
- added DigiCert CA certificates to ca-bundle (#735819)
- added a new section about error states to README.FIPS (#628976)

[0.9.8e-20]
- add missing DH_check_pub_key() call when DH key is computed (#698175)

[0.9.8e-19]
- presort list of ciphers available in SSL (#688901)
- accept connection in s_server even if getaddrinfo() fails (#561260)
- point to openssl dgst for list of supported digests (#608639)
- fix handling of future TLS versions (#599112)
- added VeriSign Class 3 Public Primary Certification Authority - G5
   and StartCom Certification Authority certs to ca-bundle (#675671, 
#617856)
- upstream fixes for the CHIL engine (#622003, #671484)

[0.9.8e-18]
- add SHA-2 hashes in SSL_library_init() (#676384)

[0.9.8e-17]
- fix CVE-2010-4180 - completely disable code for
   SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG (#659462)

[0.9.8e-16]
- fix CVE-2009-3245 - add missing bn_wexpand return checks (#570924)

[0.9.8e-15]
- fix CVE-2010-0433 - do not pass NULL princ to krb5_kt_get_entry which
   in the RHEL-5 and newer versions will crash in such case (#569774)

[0.9.8e-14]
- fix CVE-2009-3555 - support the safe renegotiation extension and
   do not allow legacy renegotiation on the server by default (#533125)

[0.9.8e-13]
- fix CVE-2009-2409 - drop MD2 algorithm from EVP tables (#510197)
- fix CVE-2009-4355 - do not leak memory when CRYPTO_cleanup_all_ex_data()
   is called prematurely by application (#546707)




More information about the Oraclevm-errata mailing list