Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51528
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLA-2002:513
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory CLA-2002:513.

OpenSSL implements the Secure Sockets Layer (SSL v2/v3) and Transport
Layer Security (TLS v1) protocols as well as full-strength general
purpose cryptography functions. It's used (as a library) by several
projects, like Apache, OpenSSH, Bind, OpenLDAP and many others
clients and servers programs.

While conducting a security review of OpenSSL under the DARPA CHATS
program[1], A.L Digital and The Bunker found some buffer overflow
vulnerabilities in OpenSSL prior to (and including) versions 0.9.6e
and 0.9.7-beta2 (development).

Neophasis consultants indenpendently discovered one of these buffer
overflows and demonstrated that it was exploitable, although the
exploit is not released at this time.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CVE-2002-0655, CVE-2002-0656 and CVE-2002-0657 to
these issues.

Adi Stav and James Yonan
independently found another vulnerability which affects the ASN.1
parser.

This update fix these vulnerabilites and also adds various sanity
checks to avoid potential buffer overflows.

A complete advisory provided by the OpenSSL team is available[2] in
their website.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.darpa.mil/ito/research/chats
http://www.openssl.org/news/secadv_20020730.txt
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0655
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0656
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0657
https://secure1.securityspace.com/smysecure/catid.html?in=CLA-2002:513
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-0655
BugTraq ID: 5364
http://www.securityfocus.com/bid/5364
Bugtraq: 20020730 GLSA: OpenSSL (Google Search)
Bugtraq: 20020730 OpenSSL Security Altert - Remote Buffer Overflows (Google Search)
Bugtraq: 20020730 OpenSSL patches for other versions (Google Search)
Bugtraq: 20020730 TSLSA-2002-0063 - openssl (Google Search)
Bugtraq: 20020730 [OpenPKG-SA-2002.008] OpenPKG Security Advisory (openssl) (Google Search)
Caldera Security Advisory: CSSA-2002-033.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.0.txt
Caldera Security Advisory: CSSA-2002-033.1
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.1.txt
http://www.cert.org/advisories/CA-2002-23.html
CERT/CC vulnerability note: VU#308891
http://www.kb.cert.org/vuls/id/308891
Conectiva Linux advisory: CLA-2002:513
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000513
Debian Security Information: DSA-136 (Google Search)
En Garde Linux Advisory: ESA-20020730-019
FreeBSD Security Advisory: FreeBSD-SA-02:33
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:33.openssl.asc
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-046.php
RedHat Security Advisories: RHSA-2002:155
SuSE Security Announcement: SuSE-SA:2002:027 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2002-0656
BugTraq ID: 5362
http://www.securityfocus.com/bid/5362
BugTraq ID: 5363
http://www.securityfocus.com/bid/5363
CERT/CC vulnerability note: VU#102795
http://www.kb.cert.org/vuls/id/102795
CERT/CC vulnerability note: VU#258555
http://www.kb.cert.org/vuls/id/258555
http://www.iss.net/security_center/static/9714.php
http://www.iss.net/security_center/static/9716.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-0657
BugTraq ID: 5361
http://www.securityfocus.com/bid/5361
Bugtraq: 20020730 OpenSSL Security Altert - Remote Buffer Overflows: (Google Search)
CERT/CC vulnerability note: VU#561275
http://www.kb.cert.org/vuls/id/561275
http://www.iss.net/security_center/static/9715.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.