ALAS-2014-273


Amazon Linux 1 Security Advisory: ALAS-2014-273
Advisory Release Date: 2014-01-14 15:56 Pacific
Advisory Updated Date: 2014-09-16 22:16 Pacific
Severity: Important

Issue Overview:

A flaw was found in the way OpenSSL determined which hashing algorithm to use when TLS protocol version 1.2 was enabled. This could possibly cause OpenSSL to use an incorrect hashing algorithm, leading to a crash of an application using the library. (CVE-2013-6449)

It was discovered that the Datagram Transport Layer Security (DTLS) protocol implementation in OpenSSL did not properly maintain encryption and digest contexts during renegotiation. A lost or discarded renegotiation handshake packet could cause a DTLS client or server using OpenSSL to crash. (CVE-2013-6450)

A NULL pointer dereference flaw was found in the way OpenSSL handled TLS/SSL protocol handshake packets. A specially crafted handshake packet could cause a TLS/SSL client using OpenSSL to crash. (CVE-2013-4353)


Affected Packages:

openssl


Issue Correction:
Run yum update openssl to update your system.

New Packages:
i686:
    openssl-static-1.0.1e-4.55.amzn1.i686
    openssl-perl-1.0.1e-4.55.amzn1.i686
    openssl-1.0.1e-4.55.amzn1.i686
    openssl-devel-1.0.1e-4.55.amzn1.i686
    openssl-debuginfo-1.0.1e-4.55.amzn1.i686

src:
    openssl-1.0.1e-4.55.amzn1.src

x86_64:
    openssl-debuginfo-1.0.1e-4.55.amzn1.x86_64
    openssl-1.0.1e-4.55.amzn1.x86_64
    openssl-static-1.0.1e-4.55.amzn1.x86_64
    openssl-perl-1.0.1e-4.55.amzn1.x86_64
    openssl-devel-1.0.1e-4.55.amzn1.x86_64