Site icon 지락문화예술공작단

USN-2863-1: OpenSSL vulnerability

Ubuntu Security Notice USN-2863-1

7th January, 2016

openssl vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

Summary

OpenSSL could be made to expose sensitive information over the network.

Software description

Details

Karthikeyan Bhargavan and Gaetan Leurent discovered that OpenSSL
incorrectly allowed MD5 to be used for TLS 1.2 connections. If a remote
attacker were able to perform a man-in-the-middle attack, this flaw could
be exploited to view sensitive information.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 12.04 LTS:
libssl1.0.0

1.0.1-4ubuntu5.33

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

CVE-2015-7575

Source: ubuntu-usn

Exit mobile version