Executive Summary
Summary | |
---|---|
Title | openssl security update |
Informations | |||
---|---|---|---|
Name | RHSA-2016:2802 | First vendor Publication | 2016-11-17 |
Vendor | RedHat | Last vendor Modification | 2016-11-17 |
Severity (Vendor) | N/A | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.8 | Attack Range | Network |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: An update for openssl is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.5 Telco Extended Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node EUS (v. 6.7) - x86_64 Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.2) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.4) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server AUS (v. 6.6) - x86_64 Red Hat Enterprise Linux Server EUS (v. 6.7) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.2) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.4) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.6) - x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 6.7) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 6.6) - x86_64 Red Hat Enterprise Linux Server TUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server TUS (v. 6.6) - x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * A memory leak flaw was found in the way OpenSSL handled TLS status request extension data during session renegotiation. A remote attacker could cause a TLS server using OpenSSL to consume an excessive amount of memory and, possibly, exit unexpectedly after exhausting all available memory, if it enabled OCSP stapling support. (CVE-2016-6304) Red Hat would like to thank the OpenSSL project for reporting this issue. Upstream acknowledges Shi Lei (Gear Team of Qihoo 360 Inc.) as the original reporter. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 1377600 - CVE-2016-6304 openssl: OCSP Status Request extension unbounded memory growth |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2016-2802.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-401 | Failure to Release Memory Before Removing Last Reference ('Memory Leak') |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2016-11-08 | OpenSSL OCSP Status Request Extension denial of service attempt RuleID : 40360 - Revision : 3 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-02-28 | Name : The version of Arista Networks EOS running on the remote device is affected b... File : arista_eos_sa0024_4_17.nasl - Type : ACT_GATHER_INFO |
2017-10-20 | Name : A network management system installed on the remote host is affected by multi... File : oracle_ilom_3_2_6.nasl - Type : ACT_GATHER_INFO |
2017-08-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2017-2493.nasl - Type : ACT_GATHER_INFO |
2017-07-20 | Name : A web application installed on the remote host is affected by multiple vulner... File : oracle_e-business_cpu_jul_2017.nasl - Type : ACT_GATHER_INFO |
2017-06-30 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2017-1658.nasl - Type : ACT_GATHER_INFO |
2017-06-26 | Name : The Tenable SecurityCenter application on the remote host contains an OpenSSL... File : securitycenter_openssl_1_0_1u.nasl - Type : ACT_GATHER_INFO |
2017-05-02 | Name : An application installed on the remote host is affected by multiple vulnerabi... File : oracle_secure_global_desktop_apr_2017_cpu.nasl - Type : ACT_GATHER_INFO |
2017-05-01 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2016-1047.nasl - Type : ACT_GATHER_INFO |
2017-04-21 | Name : An enterprise management application installed on the remote host is affected... File : oracle_enterprise_manager_apr_2017_cpu.nasl - Type : ACT_GATHER_INFO |
2017-02-15 | Name : An application running on the remote host is affected by multiple vulnerabili... File : nessus_tns_2016_16.nasl - Type : ACT_GATHER_INFO |
2017-01-25 | Name : A web application running on the remote host is affected by multiple vulnerab... File : mysql_enterprise_monitor_3_3_1_1112.nasl - Type : ACT_GATHER_INFO |
2017-01-25 | Name : A web application running on the remote host is affected by multiple vulnerab... File : mysql_enterprise_monitor_3_2_5_1141.nasl - Type : ACT_GATHER_INFO |
2017-01-25 | Name : A web application running on the remote host is affected by multiple vulnerab... File : mysql_enterprise_monitor_3_1_5_7958.nasl - Type : ACT_GATHER_INFO |
2017-01-06 | Name : A vulnerability scanner installed on the remote host is affected by multiple ... File : pvs_5_2_0.nasl - Type : ACT_GATHER_INFO |
2017-01-05 | Name : The remote device is missing a vendor-supplied security patch. File : juniper_jsa10759.nasl - Type : ACT_GATHER_INFO |
2016-12-27 | Name : An application running on the remote web server is affected by multiple vulne... File : ibm_bigfix_remote_control_9_1_3.nasl - Type : ACT_GATHER_INFO |
2016-12-16 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_SecUpd2016-007.nasl - Type : ACT_GATHER_INFO |
2016-12-16 | Name : The remote host is missing a macOS update that fixes multiple security vulner... File : macos_10_12_2.nasl - Type : ACT_GATHER_INFO |
2016-12-07 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201612-16.nasl - Type : ACT_GATHER_INFO |
2016-11-22 | Name : The remote AIX host has a version of OpenSSL installed that is affected by mu... File : aix_openssl_advisory21.nasl - Type : ACT_GATHER_INFO |
2016-11-17 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-2802.nasl - Type : ACT_GATHER_INFO |
2016-11-15 | Name : The remote Fedora host is missing a security update. File : fedora_2016-64e0743e16.nasl - Type : ACT_GATHER_INFO |
2016-11-14 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1289.nasl - Type : ACT_GATHER_INFO |
2016-11-11 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1283.nasl - Type : ACT_GATHER_INFO |
2016-11-03 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL54211024.nasl - Type : ACT_GATHER_INFO |
2016-10-21 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_34_rpm.nasl - Type : ACT_GATHER_INFO |
2016-10-21 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_16_rpm.nasl - Type : ACT_GATHER_INFO |
2016-10-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_16.nasl - Type : ACT_GATHER_INFO |
2016-10-20 | Name : An application installed on the remote host is affected by multiple vulnerabi... File : virtualbox_5_1_8.nasl - Type : ACT_GATHER_INFO |
2016-10-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_34.nasl - Type : ACT_GATHER_INFO |
2016-10-17 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1189.nasl - Type : ACT_GATHER_INFO |
2016-10-12 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1172.nasl - Type : ACT_GATHER_INFO |
2016-10-12 | Name : The remote Fedora host is missing a security update. File : fedora_2016-97454404fe.nasl - Type : ACT_GATHER_INFO |
2016-10-07 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2468-1.nasl - Type : ACT_GATHER_INFO |
2016-10-06 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2458-1.nasl - Type : ACT_GATHER_INFO |
2016-09-30 | Name : The remote service is affected by multiple vulnerabilities. File : openssl_1_1_0a.nasl - Type : ACT_GATHER_INFO |
2016-09-30 | Name : The remote service is affected by multiple vulnerabilities. File : openssl_1_0_2i.nasl - Type : ACT_GATHER_INFO |
2016-09-30 | Name : The remote service is affected by multiple vulnerabilities. File : openssl_1_0_1u.nasl - Type : ACT_GATHER_INFO |
2016-09-29 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160927_openssl_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote OracleVM host is missing a security update. File : oraclevm_OVMSA-2016-0135.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-1940.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote Fedora host is missing a security update. File : fedora_2016-a555159613.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1130.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1134.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-1940.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1940.nasl - Type : ACT_GATHER_INFO |
2016-09-28 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2394-1.nasl - Type : ACT_GATHER_INFO |
2016-09-27 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2387-1.nasl - Type : ACT_GATHER_INFO |
2016-09-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-3087-2.nasl - Type : ACT_GATHER_INFO |
2016-09-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-637.nasl - Type : ACT_GATHER_INFO |
2016-09-23 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2016-266-01.nasl - Type : ACT_GATHER_INFO |
2016-09-23 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-3087-1.nasl - Type : ACT_GATHER_INFO |
2016-09-23 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_43eaa65680bc11e6bf52b499baebfeaf.nasl - Type : ACT_GATHER_INFO |
2016-09-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3673.nasl - Type : ACT_GATHER_INFO |
2016-09-23 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2016-749.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-11-18 13:25:41 |
|
2016-11-17 17:23:15 |
|