Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Ubuntu 13.04 on me high-end box - Horrible
· NVIDIA GeForce Chips Comparison Table and more
· CSF 6.09 released
· Microsoft and Google agree to build YouTube app for Windows Phone 8
· OS X 10.8.4 Build 12E55 Seeded to Developers
· Wine 1.5.31 released
· Libxvmc/Libx11 Updates for Debian
· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?

Upcoming News
· [Tech ARP] BIOS Option Of The Week - Hardware Prefetcher
· SuperTooth HD VOICE Bluetooth Speakerphone Review @ TestFreaks
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0
· [security-announce] SUSE-SU-2013:0819-2: critical: Security update for Linux kernel
· Fractal Design Node 605 Silent HTPC Case Review @ Legit Reviews

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Easy to watch UFC 160 Live streaming
by: julianbarter0r
on: 2013-05-25 11:29
0 replies, 17 views

· Easy to watch UFC 160 Live Stream online
by: julianbarter0r
on: 2013-05-25 11:28
0 replies, 19 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6505 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 715 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4606 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » November 2004 » USN-24-1: openssl script vulnerability

USN-24-1: openssl script vulnerability

Posted by Philipp Esselbach on: 11/11/2004 05:35 PM [ Print | 0 comment(s) ]

An OpenSSL security update is available for Ubuntu Linux 4.10

==========================================================
Ubuntu Security Notice USN-24-1 November 11, 2004
openssl script vulnerability
CAN-2004-0975
==========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

openssl

The problem can be corrected by upgrading the affected package to version 0.9.7d-3ubuntu0.1. In general, a standard system upgrade is sufficient to effect the necessary changes.




Details follow:

Recently, Trustix Secure Linux discovered a vulnerability in the openssl package. The auxiliary script "der_chop" created temporary files in an insecure way, which could allow a symlink attack to create or overwrite arbitrary files with the privileges of the user invoking the program.

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/o/openssl/openssl_0.9.7d-3ubuntu0.1.diff.gz
Size/MD5: 25295 881c617310b90b1a23170c3af67b1326
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/openssl_0.9.7d-3ubuntu0.1.dsc
Size/MD5: 636 9ac30cc189e6af361873ef8bbae464de
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/openssl_0.9.7d.orig.tar.gz
Size/MD5: 2799796 533b7f758325d74c1e01e67994e3ae59

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/o/openssl/libssl-dev_0.9.7d-3ubuntu0.1_amd64.deb
Size/MD5: 2676308 b01867418c6f2a038be827927fdd00aa
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/libssl0.9.7_0.9.7d-3ubuntu0.1_amd64.deb
Size/MD5: 696844 18ab0899bd1532f1ad91f41dd65f08d4
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/openssl_0.9.7d-3ubuntu0.1_amd64.deb
Size/MD5: 899612 711904323e819ac90f7aad08f1bc3631

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/o/openssl/libssl-dev_0.9.7d-3ubuntu0.1_i386.deb
Size/MD5: 2477088 8914e8d13dc84b1756bec1c4b19ac2a5
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/libssl0.9.7_0.9.7d-3ubuntu0.1_i386.deb
Size/MD5: 2152878 ff51693973742936138ad42c90fb065e
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/openssl_0.9.7d-3ubuntu0.1_i386.deb
Size/MD5: 898268 adb9c7c755a144f8c5a8bc1bdc157b44

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/o/openssl/libssl-dev_0.9.7d-3ubuntu0.1_powerpc.deb
Size/MD5: 2759022 1d316d0e83b4b4686d91a7e92512c6ca
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/libssl0.9.7_0.9.7d-3ubuntu0.1_powerpc.deb
Size/MD5: 700616 aef52c3c1fdeaa12773691b3bac4f57d
http://security.ubuntu.com/ubuntu/pool/main/o/openssl/openssl_0.9.7d-3ubuntu0.1_powerpc.deb
Size/MD5: 904250 b2b9f62f80982a8ea6d20ce5fc06884d


Bookmark and Share

« Western Digital Raptor WD740GD Review · USN-23-1: apache2 vulnerability »

Linux Compatible » News » November 2004 » USN-24-1: openssl script vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition