Bug 44751 - openssl: multiple issues (4.2)
openssl: multiple issues (4.2)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.2
Other Linux
: P5 normal (vote)
: UCS 4.2-0-errata
Assigned To: Philipp Hahn
Arvid Requate
:
: 43934 (view as bug list)
Depends on:
Blocks: 44741 44817 44884
  Show dependency treegraph
 
Reported: 2017-06-08 13:10 CEST by Philipp Hahn
Modified: 2017-06-29 08:51 CEST (History)
2 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score: 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Philipp Hahn univentionstaff 2017-06-08 13:10:11 CEST
The openssl version in UCS 4.1 is affected by this issue:
* Montgomery multiplication may produce incorrect results (CVE-2016-7055)
* SSL/TLS SSL3_AL_WARNING undefined alert DoS (CVE-2016-8610)
* Truncated packet could crash via OOB read (CVE-2017-3731)
* BN_mod_exp may produce incorrect results on x86_64 (CVE-2017-3732)
Comment 1 Philipp Hahn univentionstaff 2017-06-08 13:12:20 CEST
r80070 | Bug #44751: OpenSSL 1.0.2k

See Bug #42925 comment 3 for more details
Comment 2 Philipp Hahn univentionstaff 2017-06-08 14:00:10 CEST
*** Bug 43934 has been marked as a duplicate of this bug. ***
Comment 3 Arvid Requate univentionstaff 2017-06-15 17:45:07 CEST
Works
Comment 4 Janek Walkenhorst univentionstaff 2017-06-15 18:00:03 CEST
<http://errata.software-univention.de/ucs/4.2/45.html>
Comment 5 Philipp Hahn univentionstaff 2017-06-26 10:28:38 CEST
r80475 | Bug #44751 test: Skip EXPORT and LOW cipher test

Package: ucs-test
Version: 7.0.22-3A~4.2.0.201706261021
Branch: ucs_4.2-0
Scope: errata4.2-1