FYI…
OpenSSL patches 4 vulnerabilities
- https://www.us-cert.gov/ncas/current-activity/2014/10/16/OpenSSL-Patches-Four-Vulnerabilities
Oct 16, 2014 - "OpenSSL has released updates patching four vulnerabilities, some of which may allow an attacker to cause a Denial of Service (DoS) condition or execute man-in-the-middle attacks. The following updates are available:
OpenSSL 1.0.1 users should upgrade to 1.0.1j
OpenSSL 1.0.0 users should upgrade to 1.0.0o
OpenSSL 0.9.8 users should upgrade to 0.9.8zc
US-CERT recommends users and administrators review the OpenSSL Security Advisory* for additional information and apply the necessary updates."
* https://www.openssl.org/news/secadv_20141015.txt
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3513- 7.1 (HIGH)
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566- 4.3
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3567- 7.1 (HIGH)
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3568- 4.3
Last revised: 03/16/2015
___
- http://www.securitytracker.com/id/1031053
Oct 15 2014
- http://www.securitytracker.com/id/1031052
Oct 15 2014
![]()