[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 421-1] openssl security update



Package        : openssl
Version        : 0.9.8o-4squeeze23
CVE ID         : CVE-2015-3197

CVE-2015-3197:
A malicious client can negotiate SSLv2 ciphers that have been disabled on the
server and complete SSLv2 handshakes even if all SSLv2 ciphers have been
disabled, provided that the SSLv2 protocol was not also disabled via
SSL_OP_NO_SSLv2.

Additionally, when using a DHE cipher suite a new DH key will always be
generated for each connection.


This will be the last security update for the squeeze version of the package.
The 0.9.8 version is no longer supported and the squeeze LTS support will end
soon.  If you are using openssl you should upgrade to wheezy or preferably
jessie.  The version in those versions contain many security improvements.


Kurt Roeckx

Attachment: signature.asc
Description: PGP signature


Reply to: