QID 198771
Date Published: 2022-05-05
QID 198771: Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-5402-1)
Openssl incorrectly handled the c_rehashscript.
Openssl incorrectly verified certain responsesigning certificates.
Openssl used the incorrect mac key in therc4-md5 ciphersuite.
Openssl incorrectly handled resources whendecoding certificates and keys.
A local attacker could possibly use this issue to execute arbitrarycommands when c_rehash is run.
A remote attacker could possibly use this issue tospoof certain response signing certificates.
In non-default configurations were rc4-md5 is enabled,a remote attacker could possibly use this issue to modify encryptedcommunications.
A remote attacker could possibly use thisissue to cause openssl to consume resources, leading to a denial ofservice.
Solution
Refer to Ubuntu security advisory USN-5402-1 for updates and patch information.
Vendor References
- USN-5402-1 -
ubuntu.com/security/notices/USN-5402-1
CVEs related to QID 198771
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-5402-1 | Ubuntu Linux |
|