OpenSSL v1.0.0a - 0.9.8o released
- http://secunia.com/advisories/40024/
Release Date: 2010-06-02
Criticality level: Moderately critical
Impact: Spoofing, DoS, System access
Where: From remote
Solution: Update to version 1.0.0a.
- http://secunia.com/advisories/40000/
Solution: Update to version 0.9.8o.
Original Advisory: http://www.openssl.org/news/secadv_20100601.txt
[01-Jun-2010] - "OpenSSL Security Advisory…
Two security flaws have been fixed in OpenSSL 0.9.8o and OpenSSL 1.0.0a. Invalid ASN1 module definition for CMS
CMS structures containing OriginatorInfo are mishandled this can write to invalid memory addresses or free up memory twice (CVE-2010-0742). This bug is only present in the CMS code: the older PKCS#7 code is not affected. CMS is only present in OpenSSL 0.9.8h and later where it is -disabled- by default and 1.0.0 where it is -enabled- by default. Users of OpenSSL CMS code should update to 0.9.8o or 1.0.0a which contains a patch to correct this issue… Invalid Return value check in pkey_rsa_verifyrecover
When verification recovery fails for RSA keys an uninitialised buffer with an undefined length is returned instead of an error code (CVE-2010-1633). This bug is only present in OpenSSL 1.0.0 and only affects applications that call the function EVP_PKEY_verify_recover(). As this function is not present in previous versions of OpenSSL and not used by OpenSSL internal code very few applications should be affected. The OpenSSL utility application "pkeyutl" does use this function. Affected users should update to 1.0.0a which contains a patch to correct this bug…
- http://www.openssl.org/source/
- https://secunia.com/advisories/47426/
Release Date: 2012-01-05
Criticality level: Moderately critical
Impact: Exposure of sensitive information, DoS, System access
Where: From remote
Solution: Update to version 0.9.8s or 1.0.0f.
- http://www.securitytracker.com/id/1029557
CVE Reference: CVE-2013-4353
Jan 7 2014
Impact: Denial of service via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 1.0.1x prior to 1.0.1f…
Solution: The vendor has issued a fix (1.0.1f)…
- https://atlas.arbor.net/briefs/index#-918139434 Extreme Severity
17 Apr 2014 - "Repurcussions from the OpenSSL Heartbleed vulnerability disclosed last week continues, with potentially compromised certificates still being used and multiple applications and devices still affected by the OpenSSL flaw…"
___
OpenSSL TLS Heartbeat - 1.0.1g
- http://www.securitytracker.com/id/1030026
CVE Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0160
Updated: Apr 11 2014
Impact: Disclosure of authentication information, Disclosure of system information, Disclosure of user information
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 1.0.1 through 1.0.1f; 1.0.2-beta …
Impact: A remote user can obtain potentially sensitive information, including encryption keys.
Solution: The vendor has issued a fix (1.0.1g; fix pending for 1.0.2-beta2).
The vendor's advisory is available at:
- http://www.openssl.org/news/secadv_20140407.txt
"… Affected users should upgrade to OpenSSL 1.0.1g. Users unable to immediately
upgrade can alternatively recompile OpenSSL with -DOPENSSL_NO_HEARTBEATS.
1.0.2 will be fixed in 1.0.2-beta2."
- https://secunia.com/advisories/57347/
Last Update: 2014-04-10
Where: From remote
Impact: Exposure of sensitive information…
CVE Reference(s): CVE-2014-0160
… vulnerability is reported in versions 1.0.1 through 1.0.1f.
Solution: Update to version 1.0.1g.
___
Android OpenSSL TLS Heartbeat vuln
- https://secunia.com/advisories/57386/
Release Date: 2014-04-10
Criticality: Moderately Critical
Where: From remote
Impact: Exposure of sensitive information
Solution Status: Vendor Patch
Operating System: Android 4.x
CVE Reference(s): CVE-2014-0160
… vulnerability is caused due to a bundled vulnerable version of OpenSSL.
For more information: https://secunia.com/SA57347/
The vulnerability is reported in version 4.1.1…
Original Advisory:
- http://googleonlinesecurity.blogspot.com/2014/04/google-services-updated-to-address.html
April 9, 2014 Apr 12, Apr 14, Apr 16: Updated…
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0195 - 6.8 Last revised: 06/26/2014 - "… OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h… allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment…"
- http://www.securitytracker.com/id/1030336
CVE Reference: CVE-2014-0224
Jun 5 2014
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to versions 0.9.8za, 1.0.0m, 1.0.1h …
Impact: A remote user can conduct a man-in-the-middle attack to decrypt and modify data.
Solution: The vendor has issued a fix (0.9.8za, 1.0.0m, 1.0.1h)…
The vendor's advisory is available at:
- http://www.openssl.org/news/secadv_20140605.txt
- https://atlas.arbor.net/briefs/
Scanned OpenSSL Servers Vulnerable to Recent MITM Vulnerability High Severity
June 20, 2014
A recent scan conducted by Qualys* shows that 49% of OpenSSL servers remain vulnerable to the SSL/TLS MITM (Man-in-the-Middle) vulnerability disclosed earlier this month. Analysis: About 14% are exploitable, as they are running a newer version of OpenSSL (1.0.1). [ http://blog.ivanristic.com/2014/06/ssl-pulse-49-percent-vulnerable-to-cve-2014-0224-in-june-2014.html ] While the vulnerability (CVE-2014-0224**) was only publicly disclosed this month, along with several other security issues [ https://www.openssl.org/news/secadv_20140605.txt ], it has likely been present since 1998. The MITM vulnerability could allow an attacker to intercept and decrypt traffic between vulnerable clients and servers. Users should ensure that any vulnerable installations of OpenSSL detailed in the advisory are upgraded as soon as possible. As demonstrated by the effects of the OpenSSL Heartbleed vulnerability several months ago, many devices including servers, applications, websites, and email/messaging clients, are greatly impacted by OpenSSL security issues…
* https://community.qualys.com/blogs/securitylabs/2014/06/13/ssl-pulse-49-vulnerable-to-cve-2014-0224-14-exploitable
- http://blog.erratasec.com/2014/06/300k-vulnerable-to-heartbleed-two.html
June 21, 2014 - "When the Heartbleed vulnerability was announced, we found 600k systems vulnerable. A month later, we found that half had been patched, and only 300k were vulnerable. Last night, now slightly over two months after Heartbleed, we scanned again, and found 300k (309,197) still vulnerable. This is done by simply scanning on port 443, I haven't checked other ports…"
A flaw in OBJ_obj2txt may cause pretty printing functions such as
X509_name_oneline, X509_name_print_ex et al. to leak some information from the
stack. Applications may be affected if they echo pretty printing output to the
attacker. OpenSSL SSL/TLS clients and servers themselves are not affected.
OpenSSL 0.9.8 users should upgrade to 0.9.8zb
OpenSSL 1.0.0 users should upgrade to 1.0.0n.
OpenSSL 1.0.1 users should upgrade to 1.0.1i.
… The issue affects OpenSSL clients and allows a malicious server to crash
the client with a null pointer dereference (read) by specifying an SRP
ciphersuite even though it was not properly negotiated with the client. This can
be exploited through a Denial of Service attack.
OpenSSL 1.0.1 SSL/TLS client users should upgrade to 1.0.1i …"
___
- http://www.securitytracker.com/id/1030693
CVE Reference: CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3508, CVE-2014-3509, CVE-2014-3510, CVE-2014-3511, CVE-2014-3512, CVE-2014-5139
Aug 7 2014
Impact: Denial of service via network, Disclosure of system information, Execution of arbitrary code via network, Modification of system information, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to versions 0.9.8zb, 1.0.0n, 1.0.1i …