USN-3087-1: OpenSSL vulnerabilities
USN-3087-1: OpenSSL vulnerabilities Ubuntu Security Notice USN-3087-1 22nd September, 2016 openssl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in OpenSSL. Software description openssl – Secure Socket Layer (SSL) cryptographic library and tools Details Shi Lei discovered that OpenSSL incorrectly handled the OCSP Status Requestextension. A remote attacker could possibly use this issue to cause memoryconsumption, resulting in a denial of service. (CVE-2016-6304) Guido Vranken discovered that OpenSSL used undefined behaviour whenperforming pointer arithmetic. A remote attacker could possibly use thisissue to cause OpenSSL to crash, resulting in a denial of service. Thisissue has only been addressed in Ubuntu 16.04 LTS in this update.(CVE-2016-2177) César Pereida, Billy Brumley, and Yuval Yarom discovered that OpenSSLdid not properly use constant-time operations when performing [ more… ]