CentOS Icon CentOS Logo
CentOS Text
   
  
www.centos.org Forum Index
   CentOS 6 - Security Support
  openss 1.3.2

 

 Bottom   Previous Topic   Next Topic
  •  Rate Thread
      Rate this Thread
      Excellent
      Good
      Average
      Bad
      Terrible
Poster Thread
  •  rvakili
      rvakili
openss 1.3.2
#1
Newbie
Joined: 2012/4/19
From
Posts: 2
Hi All,

I, am sure, you are aware of the Multiple vulnerabilities were reported in the ASN.1 parsing code in OpenSSL. I am wondering as how to update my openssl.

With many thanks in advance.
Posted on: 2012/4/19 21:03
Create PDF from Post Print
Top
  •  pschaff
      pschaff
Re: openss 1.3.2
#2
Moderator
Joined: 2006/12/13
From Tidewater, Virginia, North America
Posts: 18773
Welcome to the CentOS fora. Please see the recommended reading for new users linked in my signature.

FAQ#20. Where can I get the latest version of XyZ.rpm for CentOS? I cannot find it anywhere.

Pay attention to the part about backporting.
_________________
Phil

Recommended reading: FAQ & Readme first ; Search hint: google "your topic site:centos.org"; Smart Questions
Posted on: 2012/4/19 23:43
Create PDF from Post Print
Top
  •  TrevorH
      TrevorH
Re: openss 1.3.2
#3
Moderator
Joined: 2009/9/24
From Brighton, UK
Posts: 6306
I can't see any vulnerabilities in the ASN.1 parsing in openssl listed here newer than 2009 and they're fixed in openssl 0.9.8k so CentOS 6 is not vulnerable with its openssl-1.0.0-20.el6_2.3 package. On CentOS 5 you can check for specific CVE numbers by running, e.g.

$ rpm -q --changelog openssl | grep CVE-2009-0590
- fix CVE-2009-0590 - reject incorrectly encoded ASN.1 strings (#492304)
$ rpm -q openssl
openssl-0.9.8e-22.el5_8.1
_________________
Linux/VoIP Systems Administrator
Posted on: 2012/4/20 0:57
Create PDF from Post Print
Top
 Top   Previous Topic   Next Topic

 


 You cannot start a new topic.
 You can view topic.
 You cannot reply to posts.
 You cannot edit your posts.
 You cannot delete your posts.
 You cannot add new polls.
 You cannot vote in polls.
 You cannot attach files to posts.
 You cannot post without approval.




"Linux" is a registered trademark of Linus Torvalds. | All other trademarks are property of their respective owners. | All other content is Copyright @ 2004-2009 by the CentOS Project or "each individual contributor (forums, comments, etc.) unless otherwise assigned".| Theme based on a theme by 7dana.com