Boletines de Vulnerabilidades

DSA-2998 openssl - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Multiple vulnerabilities have been identified in OpenSSL, a SecureSockets Layer toolkit, that may result in denial of service(application crash, large memory consumption), information leak,protocol downgrade. Additionally, a buffer overrun affecting onlyapplications explicitly set up for SRP has been fixed (CVE-2014-3512).

More info:

https://www.debian.org/security/2014/dsa-2998

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3505 ,CVE-2014-3506 ,CVE-2014-3507 ,CVE-2014-3508 ,CVE-2014-3509 ,CVE-2014-3510 ,CVE-2014-3511 ,CVE-2014-3512 ,CVE-2014-5139 and DSA-2998.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-08

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT